Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.002 Archive via Library |
MalwareZLib | The ZLib backdoor compresses communications using the standard Zlib compression library. |
| T1560.002 Archive via Library |
MalwareInvisiMole | InvisiMole can use zlib to compress and decompress data. |
| T1560.002 Archive via Library |
MalwareBBSRAT | BBSRAT can compress data with ZLIB prior to sending it back to the C2 server. |
| T1560.002 Archive via Library |
MalwareSeaDuke | SeaDuke compressed data with zlib prior to sending it over C2. |
| T1560.002 Archive via Library |
MalwareEpic | Epic compresses the collected data with bzip2 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareFoggyWeb | FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class. |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareTajMahal | TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files. |
| T1560.002 Archive via Library |
MalwareCardinal RAT | Cardinal RAT applies compression to C2 traffic using the ZLIB library. |
| T1560.002 Archive via Library |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib. |
| T1560.002 Archive via Library |
MalwareLunarWeb | LunarWeb can zlib-compress data prior to exfiltration. |
| T1560.002 Archive via Library |
MalwareDenis | Denis compressed collected data using zlib. |
| T1560.002 Archive via Library |
MalwareBADFLICK | BADFLICK has compressed data using the aPLib compression library. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.