ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.001×

167 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareTrickBot

TrickBot uses a custom crypter leveraging Microsoft’s CryptoAPI to encrypt C2 traffic.Newer versions of TrickBot have been known to use `bcrypt` to encrypt and digitally sign responses to their C2 server.

T1573.001
Symmetric Cryptography
MalwareBLINDINGCAN

BLINDINGCAN has encrypted its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareNinja

Ninja can XOR and AES encrypt C2 messages.

T1573.001
Symmetric Cryptography
MalwarePikabot

Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information.

T1573.001
Symmetric Cryptography
MalwareBumblebee

Bumblebee can encrypt C2 requests and responses with RC4

T1573.001
Symmetric Cryptography
MalwareTorisma

Torisma has encrypted its C2 communications using XOR and VEST-32.

T1573.001
Symmetric Cryptography
MalwareStuxnet

Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant.

T1573.001
Symmetric Cryptography
MalwareDowndelph

Downdelph uses RC4 to encrypt C2 responses.

T1573.001
Symmetric Cryptography
MalwareRotaJakiro

RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression.

T1573.001
Symmetric Cryptography
MalwareSardonic

Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers.

T1573.001
Symmetric Cryptography
MalwareEmissary

The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data.

T1573.001
Symmetric Cryptography
MalwareKEYMARBLE

KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareTAMECAT

TAMECAT has used AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareCASTLETAP

CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet.

T1573.001
Symmetric Cryptography
MalwareRedLeaves

RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear.

T1573.001
Symmetric Cryptography
MalwareFelismus

Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys.

T1573.001
Symmetric Cryptography
MalwareHavoc

Havoc can send an AES encrypted check-in request to the C2 server.

T1573.001
Symmetric Cryptography
MalwarexCaon

xCaon has encrypted data sent to the C2 server using a XOR key.

T1573.001
Symmetric Cryptography
MalwarePLAINTEE

PLAINTEE encodes C2 beacons using XOR.

T1573.001
Symmetric Cryptography
MalwareNebulae

Nebulae can use RC4 and XOR to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLurid

Lurid performs XOR encryption.

T1573.001
Symmetric Cryptography
MalwareTONESHELL

TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets.

T1573.001
Symmetric Cryptography
MalwareRainyDay

RainyDay can use RC4 to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareNETWIRE

NETWIRE can use AES encryption for C2 data transferred.

T1573.001
Symmetric Cryptography
MalwareBOOKWORM

BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1573.001
Symmetric Cryptography
MalwareHyperStack

HyperStack has used RSA encryption for C2 communications.

T1573.001
Symmetric Cryptography
MalwareHAMMERTOSS

Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command.

T1573.001
Symmetric Cryptography
MalwareCosmicDuke

CosmicDuke contains a custom version of the RC4 algorithm that includes a programming error.

T1573.001
Symmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using AES256.

T1573.001
Symmetric Cryptography
MalwareEmotet

Emotet is known to use RSA keys for encrypting C2 traffic.

T1573.001
Symmetric Cryptography
MalwareSNUGRIDE

SNUGRIDE encrypts C2 traffic using AES with a static key.

T1573.001
Symmetric Cryptography
MalwareTHINCRUST

THINCRUST can process RSA encryted C2 commands.

T1573.001
Symmetric Cryptography
MalwareMachete

Machete has used AES to exfiltrate documents.

T1573.001
Symmetric Cryptography
MalwarePrikormka

Prikormka encrypts some C2 traffic with the Blowfish cipher.

T1573.001
Symmetric Cryptography
MalwarePUBLOAD

PUBLOAD has used RC4 encryption in C2 communications.

T1573.001
Symmetric Cryptography
MalwareSystemBC

SystemBC has encrypted its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwarePingPull

PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications.

T1573.001
Symmetric Cryptography
MalwareWellMess

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.001
Symmetric Cryptography
MalwareWoody RAT

Woody RAT can use AES-CBC to encrypt data sent to its C2 server.

T1573.001
Symmetric Cryptography
MalwareMafalda

Mafalda can encrypt its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareSombRAT

SombRAT has encrypted its C2 communications with AES.

T1573.001
Symmetric Cryptography
MalwareFlawedAmmyy

FlawedAmmyy has used SEAL encryption during the initial C2 handshake.

T1573.001
Symmetric Cryptography
MalwareRifdoor

Rifdoor has encrypted command and control (C2) communications with a stream cipher.

T1573.001
Symmetric Cryptography
MalwareInvisiMole

InvisiMole uses variations of a simple XOR encryption routine for C&C communications.

T1573.001
Symmetric Cryptography
MalwareVolgmer

Volgmer uses a simple XOR cipher to encrypt traffic and files.

T1573.001
Symmetric Cryptography
MalwareZeroT

ZeroT has used RC4 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareRDAT

RDAT has used AES ciphertext to encode C2 communications.

T1573.001
Symmetric Cryptography
MalwareOkrum

Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase.

T1573.001
Symmetric Cryptography
MalwareBonadan

Bonadan can XOR-encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareRustyWater

RustyWater has encrypted encoded data with XOR before sending it to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.