ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560×

44 examples

TechniqueUsed byProcedure example
T1560
Archive Collected Data
MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

T1560
Archive Collected Data
MalwareExaramel for Windows

Exaramel for Windows automatically encrypts files before sending them to the C2 server.

T1560
Archive Collected Data
MalwareJumbledPath

JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices.

T1560
Archive Collected Data
MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

T1560
Archive Collected Data
MalwareLurid

Lurid can compress data before sending it.

T1560
Archive Collected Data
MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

T1560
Archive Collected Data
MalwareNETWIRE

NETWIRE has the ability to compress archived screenshots.

T1560
Archive Collected Data
MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

T1560
Archive Collected Data
MalwareMachete

Machete stores zipped files with profile data from installed web browsers.

T1560
Archive Collected Data
MalwarePowerLess

PowerLess can encrypt browser database files prior to exfiltration.

T1560
Archive Collected Data
MalwarePrikormka

After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish.

T1560
Archive Collected Data
MalwareLoFiSe

LoFiSe can collect files into password-protected ZIP-archives for exfiltration.

T1560
Archive Collected Data
MalwareVERMIN

VERMIN encrypts the collected files using 3-DES.

T1560
Archive Collected Data
MalwareChrommme

Chrommme can encrypt and store on disk collected data before exfiltration.

T1560
Archive Collected Data
MalwareRunningRAT

RunningRAT contains code to compress files.

T1560
Archive Collected Data
MalwareEpic

Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.

T1560
Archive Collected Data
MalwareLightNeuron

LightNeuron contains a function to encrypt and store emails that it collects.

T1560
Archive Collected Data
MalwareMuddyViper

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

T1560
Archive Collected Data
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.

T1560
Archive Collected Data
MalwareLP-Notes

LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC
and the initialization vector 91A4E6F6D51DAEE773A8F00279792578.

T1560
Archive Collected Data
MalwareSpica

Spica can archive collected documents for exfiltration.

T1560
Archive Collected Data
MalwareKONNI

KONNI has encrypted data and files prior to exfiltration.

T1560
Archive Collected Data
MalwareBLUELIGHT

BLUELIGHT can zip files before exfiltration.

T1560
Archive Collected Data
MalwareWellMail

WellMail can archive files on the compromised host.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1560
Archive Collected Data
MalwareCadelspy

Cadelspy has the ability to compress stolen data into a .cab file.

T1560
Archive Collected Data
MalwareRaccoon Stealer

Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration.

T1560
Archive Collected Data
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560
Archive Collected Data
MalwareGold Dragon

Gold Dragon encrypts data using Base64 before being sent to the command and control server.

T1560
Archive Collected Data
MalwarePillowmint

Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.

T1560
Archive Collected Data
MalwareProton

Proton zips up files before exfiltrating them.

T1560
Archive Collected Data
MalwareKessel

Kessel can RC4-encrypt credentials before sending to the C2.

T1560
Archive Collected Data
MalwareFELIXROOT

FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.

T1560
Archive Collected Data
MalwareTroll Stealer

Troll Stealer compresses stolen data prior to exfiltration.

T1560
Archive Collected Data
MalwareXCSSET

XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.

T1560
Archive Collected Data
MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

T1560
Archive Collected Data
MalwareRemexi

Remexi encrypts and adds all gathered browser data into files for upload to C2.

T1560
Archive Collected Data
MalwareLizar

Lizar has encrypted data before sending it to the server.

T1560
Archive Collected Data
MalwareDtrack

Dtrack packs collected data into a password protected archive.

T1560
Archive Collected Data
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

T1560
Archive Collected Data
ToolBloodHound

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

T1560
Archive Collected Data
ToolShimRatReporter

ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.

T1560
Archive Collected Data
ToolEmpire

Empire can ZIP directories on the target system.

T1560
Archive Collected Data
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.