Sub-technique of T1132 Data Encoding.View on attack.mitre.org
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.
Rules on DetectionCode tagged with T1132.002.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupKimsuky | Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding. |
| Used by | Procedure example |
|---|---|
| MalwareBACKSPACE | Newer variants of BACKSPACE will encode C2 communications with a custom system. |
| MalwareBankshot | Bankshot encodes commands from the control server using a range of characters and gzip. |
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2. |
| MalwareCyclops Blink | Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed. |
| MalwareHTTPTroy | HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding. |
| MalwareInvisiMole | InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests. |
| MalwareLizar | Lizar has used a complex XOR operation to obfuscate C2 communications. |
| MalwareNeo-reGeorg | Neo-reGeorg can use modified Base64 encoding to obfuscate communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.