ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.002×

80 examples

TechniqueUsed byProcedure example
T1573.002
Asymmetric Cryptography
MalwareBRICKSTORM

BRICKSTORM has communicated with C2 infrastructure via TLS.

T1573.002
Asymmetric Cryptography
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCOATHANGER

COATHANGER connects to command and control infrastructure using SSL.

T1573.002
Asymmetric Cryptography
MalwareSardonic

Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.

T1573.002
Asymmetric Cryptography
Malwareadbupd

adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareCASTLETAP

CASTLETAP can initiate a C2 connection over an SSL socket.

T1573.002
Asymmetric Cryptography
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.

T1573.002
Asymmetric Cryptography
MalwareStrongPity

StrongPity has encrypted C2 traffic using SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareTinyTurla

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareJ-magic

J-magic can communicate back to send a challenge to C2 infrastructure over SSL.

T1573.002
Asymmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using RSA-2048.

T1573.002
Asymmetric Cryptography
MalwareGomir

Gomir uses reverse proxy functionality that employs SSL to encrypt communications.

T1573.002
Asymmetric Cryptography
MalwareBOLDMOVE

BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareBADHATCH

BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes.

T1573.002
Asymmetric Cryptography
MalwareMachete

Machete has used TLS-encrypted FTP to exfiltrate data.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

T1573.002
Asymmetric Cryptography
MalwareWoody RAT

Woody RAT can use RSA-4096 to encrypt data sent to its C2 server.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareVolgmer

Some Volgmer variants use SSL to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMispadu

Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareREPTILE

REPTILE can use TLS over raw TCP for secure C2.

T1573.002
Asymmetric Cryptography
MalwareDoki

Doki has used the embedTLS library for network communications.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

T1573.002
Asymmetric Cryptography
MalwareRising Sun

Rising Sun variants can use SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareHi-Zor

Hi-Zor encrypts C2 traffic with TLS.

T1573.002
Asymmetric Cryptography
MalwareSnappyTCP

SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareGoldMax

GoldMax has RSA-encrypted its communication with the C2 server.

T1573.002
Asymmetric Cryptography
MalwarePOSHSPY

POSHSPY encrypts C2 traffic with AES and RSA.

T1573.002
Asymmetric Cryptography
MalwareDarkWatchman

DarkWatchman can use TLS to encrypt its C2 channel.

T1573.002
Asymmetric Cryptography
MalwareLumma Stealer

Lumma Stealer has used HTTPS for command and control purposes.

T1573.002
Asymmetric Cryptography
MalwareSykipot

Sykipot uses SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKEYPLUG

KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.

T1573.002
Asymmetric Cryptography
MalwarePureCrypter

PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook.

T1573.002
Asymmetric Cryptography
MalwareXTunnel

XTunnel uses SSL/TLS and RC4 to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareWannaCry

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.

T1573.002
Asymmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses RSA.

T1573.002
Asymmetric Cryptography
MalwarePay2Key

Pay2Key has used RSA encrypted communications with C2.

T1573.002
Asymmetric Cryptography
MalwareSagerunex

Sagerunex uses HTTPS for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareUroburos

Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMetamorfo

Metamorfo's C2 communication has been encrypted using OpenSSL.

T1573.002
Asymmetric Cryptography
MalwareTrojan.Karagany

Trojan.Karagany can secure C2 communications with SSL and TLS.

T1573.002
Asymmetric Cryptography
MalwareAttor

Attor's Blowfish key is encrypted with a public RSA key.

T1573.002
Asymmetric Cryptography
MalwareSodaMaster

SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareGrandoreiro

Grandoreiro can use SSL in C2 communication.

T1573.002
Asymmetric Cryptography
MalwareWellMail

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

T1573.002
Asymmetric Cryptography
MalwareBazar

Bazar can use TLS in C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKobalos

Kobalos's authentication and key exchange is performed using RSA-512.

T1573.002
Asymmetric Cryptography
MalwareHiddenFace

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCobalt Strike

Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.