Real-world descriptions of how a group, tool or campaign used a technique.
44 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560 Archive Collected Data |
MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareExaramel for Windows | Exaramel for Windows automatically encrypts files before sending them to the C2 server. |
| T1560 Archive Collected Data |
MalwareJumbledPath | JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices. |
| T1560 Archive Collected Data |
MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
| T1560 Archive Collected Data |
MalwareLurid | Lurid can compress data before sending it. |
| T1560 Archive Collected Data |
MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareNETWIRE | NETWIRE has the ability to compress archived screenshots. |
| T1560 Archive Collected Data |
MalwareAria-body | Aria-body has used ZIP to compress data gathered on a compromised host. |
| T1560 Archive Collected Data |
MalwareMachete | Machete stores zipped files with profile data from installed web browsers. |
| T1560 Archive Collected Data |
MalwarePowerLess | PowerLess can encrypt browser database files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwarePrikormka | After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish. |
| T1560 Archive Collected Data |
MalwareLoFiSe | LoFiSe can collect files into password-protected ZIP-archives for exfiltration. |
| T1560 Archive Collected Data |
MalwareVERMIN | VERMIN encrypts the collected files using 3-DES. |
| T1560 Archive Collected Data |
MalwareChrommme | Chrommme can encrypt and store on disk collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareRunningRAT | RunningRAT contains code to compress files. |
| T1560 Archive Collected Data |
MalwareEpic | Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server. |
| T1560 Archive Collected Data |
MalwareLightNeuron | LightNeuron contains a function to encrypt and store emails that it collects. |
| T1560 Archive Collected Data |
MalwareMuddyViper | MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
| T1560 Archive Collected Data |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used |
| T1560 Archive Collected Data |
MalwareLP-Notes | LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC |
| T1560 Archive Collected Data |
MalwareSpica | Spica can archive collected documents for exfiltration. |
| T1560 Archive Collected Data |
MalwareKONNI | KONNI has encrypted data and files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareBLUELIGHT | BLUELIGHT can zip files before exfiltration. |
| T1560 Archive Collected Data |
MalwareWellMail | WellMail can archive files on the compromised host. |
| T1560 Archive Collected Data |
MalwareZebrocy | Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. |
| T1560 Archive Collected Data |
MalwareCadelspy | Cadelspy has the ability to compress stolen data into a .cab file. |
| T1560 Archive Collected Data |
MalwareRaccoon Stealer | Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560 Archive Collected Data |
MalwareGold Dragon | Gold Dragon encrypts data using Base64 before being sent to the command and control server. |
| T1560 Archive Collected Data |
MalwarePillowmint | Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64. |
| T1560 Archive Collected Data |
MalwareProton | Proton zips up files before exfiltrating them. |
| T1560 Archive Collected Data |
MalwareKessel | Kessel can RC4-encrypt credentials before sending to the C2. |
| T1560 Archive Collected Data |
MalwareFELIXROOT | FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server. |
| T1560 Archive Collected Data |
MalwareTroll Stealer | Troll Stealer compresses stolen data prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareXCSSET | XCSSET will compress entire |
| T1560 Archive Collected Data |
MalwareAgent Tesla | Agent Tesla can encrypt data with 3DES before sending it over to a C2 server. |
| T1560 Archive Collected Data |
MalwareRemexi | Remexi encrypts and adds all gathered browser data into files for upload to C2. |
| T1560 Archive Collected Data |
MalwareLizar | Lizar has encrypted data before sending it to the server. |
| T1560 Archive Collected Data |
MalwareDtrack | Dtrack packs collected data into a password protected archive. |
| T1560 Archive Collected Data |
MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| T1560 Archive Collected Data |
ToolBloodHound | BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| T1560 Archive Collected Data |
ToolShimRatReporter | ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2. |
| T1560 Archive Collected Data |
ToolEmpire | Empire can ZIP directories on the target system. |
| T1560 Archive Collected Data |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.