Junk Data

T1001.001

Sub-technique of T1001 Data Obfuscation.View on attack.mitre.org

About this technique

Adversaries may add junk data to protocols used for command and control to make detection more difficult. By adding random or meaningless data to the protocols used for command and control, adversaries can prevent trivial methods for decoding, deciphering, or otherwise analyzing the traffic. Examples may include appending/prepending data with junk characters or writing junk characters between significant characters.

Detection rules0

Rules on DetectionCode tagged with T1001.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software17

Campaigns0

None recorded.

Procedure examples18

Groups1

Used byProcedure example
GroupAPT28

APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.

Software17

Used byProcedure example
MalwareBeaverTail

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

MalwareBendyBear

BendyBear has used byte randomization to obscure its behavior.

MalwareDowndelph

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

MalwareGrimAgent

GrimAgent can pad C2 messages with random generated values.

MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

MalwareMori

Mori has obfuscated the FML.dll with 200MB of junk data.

View all 17 software examples

References1

  1. FireEye SUNBURST Backdoor December 2020 Open source
    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.