ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1132.002×

17 examples

TechniqueUsed byProcedure example
T1132.002
Non-Standard Encoding
MalwareNinja

Ninja can encode C2 communications with a base64 algorithm using a custom alphabet.

T1132.002
Non-Standard Encoding
MalwareBankshot

Bankshot encodes commands from the control server using a range of characters and gzip.

T1132.002
Non-Standard Encoding
MalwareTONESHELL

TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR.

T1132.002
Non-Standard Encoding
MalwareOceanSalt

OceanSalt can encode data with a NOT operation before sending the data to the control server.

T1132.002
Non-Standard Encoding
MalwareInvisiMole

InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests.

T1132.002
Non-Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions.

T1132.002
Non-Standard Encoding
MalwareHTTPTroy

HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding.

T1132.002
Non-Standard Encoding
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2.

T1132.002
Non-Standard Encoding
MalwareUroburos

Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications.

T1132.002
Non-Standard Encoding
MalwareNightClub

NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`.

T1132.002
Non-Standard Encoding
MalwareCyclops Blink

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1132.002
Non-Standard Encoding
MalwareNeo-reGeorg

Neo-reGeorg can use modified Base64 encoding to obfuscate communications.

T1132.002
Non-Standard Encoding
MalwarePowGoop

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.

T1132.002
Non-Standard Encoding
MalwareShadowPad

ShadowPad has encoded data as readable Latin characters.

T1132.002
Non-Standard Encoding
MalwareLizar

Lizar has used a complex XOR operation to obfuscate C2 communications.

T1132.002
Non-Standard Encoding
MalwareBACKSPACE

Newer variants of BACKSPACE will encode C2 communications with a custom system.

T1132.002
Non-Standard Encoding
MalwareSmall Sieve

Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.