Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.003 Archive via Custom Method |
MalwareStuxnet | Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys. |
| T1560.003 Archive via Custom Method |
MalwareHAWKBALL | HAWKBALL has encrypted data with XOR before sending it over the C2 channel. |
| T1560.003 Archive via Custom Method |
MalwareFrameworkPOS | FrameworkPOS can XOR credit card information before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareStrongPity | StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme. |
| T1560.003 Archive via Custom Method |
MalwareNETWIRE | NETWIRE has used a custom encryption algorithm to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareMachete | Machete's collected data is encrypted with AES before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareSquirrelwaffle | Squirrelwaffle has encrypted collected data using a XOR-based algorithm. |
| T1560.003 Archive via Custom Method |
MalwareAgent.btz | Agent.btz saves system information into an XML file that is then XOR-encoded. |
| T1560.003 Archive via Custom Method |
MalwareSombRAT | SombRAT has encrypted collected data with AES-256 using a hardcoded key. |
| T1560.003 Archive via Custom Method |
MalwareFLASHFLOOD | FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareInvisiMole | InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareOkrum | Okrum has used a custom implementation of AES encryption to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareRising Sun | Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareReaver | Reaver encrypts collected data with an incremental XOR key prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareFoggyWeb | FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file. |
| T1560.003 Archive via Custom Method |
MalwareT9000 | T9000 encrypts collected data using a single byte XOR key. |
| T1560.003 Archive via Custom Method |
MalwareSPACESHIP | Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareBLUELIGHT | BLUELIGHT has encoded data into a binary blob using XOR. |
| T1560.003 Archive via Custom Method |
MalwareOopsIE | OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server. |
| T1560.003 Archive via Custom Method |
MalwareAttor | Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers. |
| T1560.003 Archive via Custom Method |
MalwareRawPOS | RawPOS encodes credit card data it collected from the victim with XOR. |
| T1560.003 Archive via Custom Method |
MalwareMESSAGETAP | MESSAGETAP has XOR-encrypted and stored contents of SMS messages that matched its target list. |
| T1560.003 Archive via Custom Method |
MalwareSUGARDUMP | SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64. |
| T1560.003 Archive via Custom Method |
MalwareOwaAuth | OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file. |
| T1560.003 Archive via Custom Method |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk. |
| T1560.003 Archive via Custom Method |
MalwareRGDoor | RGDoor encrypts files with XOR before sending them back to the C2 server. |
| T1560.003 Archive via Custom Method |
MalwareRamsay | Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR. |
| T1560.003 Archive via Custom Method |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content. |
| T1560.003 Archive via Custom Method |
MalwaremetaMain | metaMain has used XOR-based encryption for collected files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
| T1560.003 Archive via Custom Method |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.