Steganography

T1001.002

Sub-technique of T1001 Data Obfuscation.View on attack.mitre.org

About this technique

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.

Detection rules0

Rules on DetectionCode tagged with T1001.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software11

Campaigns1

Procedure examples13

Groups1

Used byProcedure example
GroupAxiom

Axiom has used steganography to hide its C2 communications.

Software11

Used byProcedure example
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

MalwareDuqu

When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.

MalwareHAMMERTOSS

HAMMERTOSS is controlled via commands that are appended to image files.

MalwareLightNeuron

LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.

MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

MalwareRDAT

RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator.

ToolSliver

Sliver can encode binary data into a .PNG file for C2 communication.

View all 11 software examples

Campaigns1

Used byProcedure example
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.