Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.001 Archive via Utility |
MalwareWindTail | WindTail has the ability to use the macOS built-in zip utility to archive files. |
| T1560.001 Archive via Utility |
MalwareInvisibleFerret | InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1560.001 Archive via Utility |
MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| T1560.001 Archive via Utility |
MalwareiKitten | iKitten will zip up the /Library/Keychains directory before exfiltrating it. |
| T1560.001 Archive via Utility |
MalwareTurian | Turian can use WinRAR to create a password-protected archive for files of interest. |
| T1560.001 Archive via Utility |
MalwarePUBLOAD | PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareInvisiMole | InvisiMole uses WinRAR to compress data that is intended to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareOkrum | Okrum was seen using a RAR archiver tool to compress/decompress data. |
| T1560.001 Archive via Utility |
MalwarePowerShower | PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwarePUNCHBUGGY | PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil. |
| T1560.001 Archive via Utility |
MalwareBeaverTail | BeaverTail has collected and archived sensitive data in a zip file. |
| T1560.001 Archive via Utility |
MalwareDustySky | DustySky can compress files via RAR while staging data to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareSagerunex | Sagerunex has archived collected materials in RAR format. |
| T1560.001 Archive via Utility |
MalwareGlassWorm | GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`. |
| T1560.001 Archive via Utility |
MalwareCORALDECK | CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareMicropsia | Micropsia creates a RAR archive based on collected files on the victim's machine. |
| T1560.001 Archive via Utility |
MalwareOopsIE | OopsIE compresses collected files with GZipStream before sending them to its C2 server. |
| T1560.001 Archive via Utility |
MalwareCrutch | Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| T1560.001 Archive via Utility |
Malwareccf32 | ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files. |
| T1560.001 Archive via Utility |
MalwareSampleCheck5000 | SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration. |
| T1560.001 Archive via Utility |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560.001 Archive via Utility |
MalwareCalisto | Calisto uses the |
| T1560.001 Archive via Utility |
MalwareRamsay | Ramsay can compress and archive collected files using WinRAR. |
| T1560.001 Archive via Utility |
MalwareLAMEHUG | LAMEHUG can xcopy for file collection on targeted systems. |
| T1560.001 Archive via Utility |
MalwarePoetRAT | PoetRAT has the ability to compress files with zip. |
| T1560.001 Archive via Utility |
MalwareIceApple | IceApple can encrypt and compress files using Gzip prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareLunarWeb | LunarWeb can create a ZIP archive with specified files and directories. |
| T1560.001 Archive via Utility |
MalwareOctopus | Octopus has compressed data before exfiltrating it using a tool called Abbrevia. |
| T1560.001 Archive via Utility |
Toolcertutil | certutil may be used to Base64 encode collected data. |
| T1560.001 Archive via Utility |
ToolPoshC2 | PoshC2 contains a module for compressing data using ZIP. |
| T1560.001 Archive via Utility |
ToolRclone | Rclone can compress files using `gzip` prior to exfiltration. |
| T1560.001 Archive via Utility |
ToolRemcos | Remcos can zip files and folders for upload. |
| T1560.001 Archive via Utility |
ToolPupy | Pupy can compress data with Zip before sending it over C2. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1560.001 Archive via Utility |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.