ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560.002×

13 examples

TechniqueUsed byProcedure example
T1560.002
Archive via Library
MalwareZLib

The ZLib backdoor compresses communications using the standard Zlib compression library.

T1560.002
Archive via Library
MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

T1560.002
Archive via Library
MalwareBBSRAT

BBSRAT can compress data with ZLIB prior to sending it back to the C2 server.

T1560.002
Archive via Library
MalwareSeaDuke

SeaDuke compressed data with zlib prior to sending it over C2.

T1560.002
Archive via Library
MalwareEpic

Epic compresses the collected data with bzip2 before sending it to the C2 server.

T1560.002
Archive via Library
MalwareFoggyWeb

FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class.

T1560.002
Archive via Library
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server.

T1560.002
Archive via Library
MalwareTajMahal

TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files.

T1560.002
Archive via Library
MalwareCardinal RAT

Cardinal RAT applies compression to C2 traffic using the ZLIB library.

T1560.002
Archive via Library
MalwareFunnyDream

FunnyDream has compressed collected files with zLib.

T1560.002
Archive via Library
MalwareLunarWeb

LunarWeb can zlib-compress data prior to exfiltration.

T1560.002
Archive via Library
MalwareDenis

Denis compressed collected data using zlib.

T1560.002
Archive via Library
MalwareBADFLICK

BADFLICK has compressed data using the aPLib compression library.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.