ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573×

11 examples

TechniqueUsed byProcedure example
T1573
Encrypted Channel
MalwareRCSession

RCSession can use an encrypted beacon to check in with C2.

T1573
Encrypted Channel
MalwareNETWIRE

NETWIRE can encrypt C2 communications.

T1573
Encrypted Channel
MalwareGomir

Gomir uses a custom encryption algorithm for content sent to command and control infrastructure.

T1573
Encrypted Channel
MalwareEmotet

Emotet has encrypted data before sending to the C2 server.

T1573
Encrypted Channel
MalwarePowerLess

PowerLess can use an encrypted channel for C2 communications.

T1573
Encrypted Channel
MalwareChaes

Chaes has used encryption for its C2 channel.

T1573
Encrypted Channel
Malwaregh0st RAT

gh0st RAT has encrypted TCP communications to evade detection.

T1573
Encrypted Channel
MalwareCryptoistic

Cryptoistic can engage in encrypted communications with C2.

T1573
Encrypted Channel
MalwareMacMa

MacMa has used TLS encryption to initialize a custom protocol for C2 communications.

T1573
Encrypted Channel
MalwarePowGoop

PowGoop can receive encrypted commands from C2.

T1573
Encrypted Channel
MalwareLizar

Lizar can support encrypted communications between the client and server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.