Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.002 Non-Standard Encoding |
MalwareNinja | Ninja can encode C2 communications with a base64 algorithm using a custom alphabet. |
| T1132.002 Non-Standard Encoding |
MalwareBankshot | Bankshot encodes commands from the control server using a range of characters and gzip. |
| T1132.002 Non-Standard Encoding |
MalwareTONESHELL | TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR. |
| T1132.002 Non-Standard Encoding |
MalwareOceanSalt | OceanSalt can encode data with a NOT operation before sending the data to the control server. |
| T1132.002 Non-Standard Encoding |
MalwareInvisiMole | InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests. |
| T1132.002 Non-Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions. |
| T1132.002 Non-Standard Encoding |
MalwareHTTPTroy | HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding. |
| T1132.002 Non-Standard Encoding |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2. |
| T1132.002 Non-Standard Encoding |
MalwareUroburos | Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications. |
| T1132.002 Non-Standard Encoding |
MalwareNightClub | NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`. |
| T1132.002 Non-Standard Encoding |
MalwareCyclops Blink | Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed. |
| T1132.002 Non-Standard Encoding |
MalwareNeo-reGeorg | Neo-reGeorg can use modified Base64 encoding to obfuscate communications. |
| T1132.002 Non-Standard Encoding |
MalwarePowGoop | PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server. |
| T1132.002 Non-Standard Encoding |
MalwareShadowPad | ShadowPad has encoded data as readable Latin characters. |
| T1132.002 Non-Standard Encoding |
MalwareLizar | Lizar has used a complex XOR operation to obfuscate C2 communications. |
| T1132.002 Non-Standard Encoding |
MalwareBACKSPACE | Newer variants of BACKSPACE will encode C2 communications with a custom system. |
| T1132.002 Non-Standard Encoding |
MalwareSmall Sieve | Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.