Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573 Encrypted Channel |
MalwareRCSession | RCSession can use an encrypted beacon to check in with C2. |
| T1573 Encrypted Channel |
MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| T1573 Encrypted Channel |
MalwareGomir | Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| T1573 Encrypted Channel |
MalwareEmotet | Emotet has encrypted data before sending to the C2 server. |
| T1573 Encrypted Channel |
MalwarePowerLess | PowerLess can use an encrypted channel for C2 communications. |
| T1573 Encrypted Channel |
MalwareChaes | Chaes has used encryption for its C2 channel. |
| T1573 Encrypted Channel |
Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| T1573 Encrypted Channel |
MalwareCryptoistic | Cryptoistic can engage in encrypted communications with C2. |
| T1573 Encrypted Channel |
MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| T1573 Encrypted Channel |
MalwarePowGoop | PowGoop can receive encrypted commands from C2. |
| T1573 Encrypted Channel |
MalwareLizar | Lizar can support encrypted communications between the client and server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.