ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560.003×

31 examples

TechniqueUsed byProcedure example
T1560.003
Archive via Custom Method
MalwareStuxnet

Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys.

T1560.003
Archive via Custom Method
MalwareHAWKBALL

HAWKBALL has encrypted data with XOR before sending it over the C2 channel.

T1560.003
Archive via Custom Method
MalwareFrameworkPOS

FrameworkPOS can XOR credit card information before exfiltration.

T1560.003
Archive via Custom Method
MalwareStrongPity

StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme.

T1560.003
Archive via Custom Method
MalwareNETWIRE

NETWIRE has used a custom encryption algorithm to encrypt collected data.

T1560.003
Archive via Custom Method
MalwareMachete

Machete's collected data is encrypted with AES before exfiltration.

T1560.003
Archive via Custom Method
MalwareSquirrelwaffle

Squirrelwaffle has encrypted collected data using a XOR-based algorithm.

T1560.003
Archive via Custom Method
MalwareAgent.btz

Agent.btz saves system information into an XML file that is then XOR-encoded.

T1560.003
Archive via Custom Method
MalwareSombRAT

SombRAT has encrypted collected data with AES-256 using a hardcoded key.

T1560.003
Archive via Custom Method
MalwareFLASHFLOOD

FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23.

T1560.003
Archive via Custom Method
MalwareInvisiMole

InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration.

T1560.003
Archive via Custom Method
MalwareOkrum

Okrum has used a custom implementation of AES encryption to encrypt collected data.

T1560.003
Archive via Custom Method
MalwareRising Sun

Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareReaver

Reaver encrypts collected data with an incremental XOR key prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareFoggyWeb

FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file.

T1560.003
Archive via Custom Method
MalwareT9000

T9000 encrypts collected data using a single byte XOR key.

T1560.003
Archive via Custom Method
MalwareSPACESHIP

Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23.

T1560.003
Archive via Custom Method
MalwareBLUELIGHT

BLUELIGHT has encoded data into a binary blob using XOR.

T1560.003
Archive via Custom Method
MalwareOopsIE

OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server.

T1560.003
Archive via Custom Method
MalwareAttor

Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers.

T1560.003
Archive via Custom Method
MalwareRawPOS

RawPOS encodes credit card data it collected from the victim with XOR.

T1560.003
Archive via Custom Method
MalwareMESSAGETAP

MESSAGETAP has XOR-encrypted and stored contents of SMS messages that matched its target list.

T1560.003
Archive via Custom Method
MalwareSUGARDUMP

SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64.

T1560.003
Archive via Custom Method
MalwareOwaAuth

OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file.

T1560.003
Archive via Custom Method
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk.

T1560.003
Archive via Custom Method
MalwareRGDoor

RGDoor encrypts files with XOR before sending them back to the C2 server.

T1560.003
Archive via Custom Method
MalwareRamsay

Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR.

T1560.003
Archive via Custom Method
MalwareFunnyDream

FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content.

T1560.003
Archive via Custom Method
MalwaremetaMain

metaMain has used XOR-based encryption for collected files before exfiltration.

T1560.003
Archive via Custom Method
MalwareADVSTORESHELL

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.

T1560.003
Archive via Custom Method
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.