ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560.001×

36 examples

TechniqueUsed byProcedure example
T1560.001
Archive via Utility
MalwareWindTail

WindTail has the ability to use the macOS built-in zip utility to archive files.

T1560.001
Archive via Utility
MalwareInvisibleFerret

InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration.

T1560.001
Archive via Utility
MalwareTONESHELL

TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives.

T1560.001
Archive via Utility
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

T1560.001
Archive via Utility
MalwareiKitten

iKitten will zip up the /Library/Keychains directory before exfiltrating it.

T1560.001
Archive via Utility
MalwareTurian

Turian can use WinRAR to create a password-protected archive for files of interest.

T1560.001
Archive via Utility
MalwarePUBLOAD

PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration.

T1560.001
Archive via Utility
MalwareInvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.

T1560.001
Archive via Utility
MalwareOkrum

Okrum was seen using a RAR archiver tool to compress/decompress data.

T1560.001
Archive via Utility
MalwarePowerShower

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.

T1560.001
Archive via Utility
MalwarePUNCHBUGGY

PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil.

T1560.001
Archive via Utility
MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

T1560.001
Archive via Utility
MalwareDustySky

DustySky can compress files via RAR while staging data to be exfiltrated.

T1560.001
Archive via Utility
MalwareSagerunex

Sagerunex has archived collected materials in RAR format.

T1560.001
Archive via Utility
MalwareGlassWorm

GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`.

T1560.001
Archive via Utility
MalwareCORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

T1560.001
Archive via Utility
MalwareMicropsia

Micropsia creates a RAR archive based on collected files on the victim's machine.

T1560.001
Archive via Utility
MalwareOopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.

T1560.001
Archive via Utility
MalwareCrutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.

T1560.001
Archive via Utility
Malwareccf32

ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files.

T1560.001
Archive via Utility
MalwareSampleCheck5000

SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration.

T1560.001
Archive via Utility
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility
MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

T1560.001
Archive via Utility
MalwareRamsay

Ramsay can compress and archive collected files using WinRAR.

T1560.001
Archive via Utility
MalwareLAMEHUG

LAMEHUG can xcopy for file collection on targeted systems.

T1560.001
Archive via Utility
MalwarePoetRAT

PoetRAT has the ability to compress files with zip.

T1560.001
Archive via Utility
MalwareIceApple

IceApple can encrypt and compress files using Gzip prior to exfiltration.

T1560.001
Archive via Utility
MalwareLunarWeb

LunarWeb can create a ZIP archive with specified files and directories.

T1560.001
Archive via Utility
MalwareOctopus

Octopus has compressed data before exfiltrating it using a tool called Abbrevia.

T1560.001
Archive via Utility
Toolcertutil

certutil may be used to Base64 encode collected data.

T1560.001
Archive via Utility
ToolPoshC2

PoshC2 contains a module for compressing data using ZIP.

T1560.001
Archive via Utility
ToolRclone

Rclone can compress files using `gzip` prior to exfiltration.

T1560.001
Archive via Utility
ToolRemcos

Remcos can zip files and folders for upload.

T1560.001
Archive via Utility
ToolPupy

Pupy can compress data with Zip before sending it over C2.

T1560.001
Archive via Utility
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration.

T1560.001
Archive via Utility
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.