Archive via Utility

T1560.001

Sub-technique of T1560 Archive Collected Data.View on attack.mitre.org

About this technique

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.

Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.

On Windows, diantz or makecab may be used to package collected files into a cabinet (.cab) file. diantz may also be used to download and compress files from remote locations (i.e. Remote Data Staging). xcopy on Windows can copy files and directories with a variety of options. Additionally, adversaries may use certutil to Base64 encode collected data before exfiltration.

Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.

Detection rules19

Rules on DetectionCode tagged with T1560.001.

Sigma13

RuleLevelLog source
Rar Usage with Password and Compression Levelhighwindows / process_creation
Suspicious Manipulation Of Default Accounts Via Net.EXEhighwindows / process_creation
7Zip Compressing Dump Filesmediumwindows / process_creation
Compress Data and Lock With Password for Exfiltration With 7-ZIPmediumwindows / process_creation
Compress Data and Lock With Password for Exfiltration With WINZIPmediumwindows / process_creation
Disk Image Mounting Via Hdiutil - MacOSmediummacos / process_creation
Winrar Compressing Dump Filesmediumwindows / process_creation
WinRAR Execution in Non-Standard Foldermediumwindows / process_creation
Cisco Stage Datalowcisco / NULL
Compressed File Creation Via Tar.EXElowwindows / process_creation
Compressed File Extraction Via Tar.EXElowwindows / process_creation
Data Compressedlowlinux / NULL
Files Added To An Archive Using Rar.EXElowwindows / process_creation

Splunk6

RuleTypeRiskData source
7zip CommandLine To SMB Share PathHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Anomalous usage of 7zipAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Renamed 7-ZipHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Renamed WinRARHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
IcedID Exfiltrated Archived File CreationHuntingNULLSysmon EventID 11
Windows Archive Collected Data via RarAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups39

Show 15 more

Software36

Show 12 more

Campaigns11

Procedure examples86

Groups39

Used byProcedure example
GroupAgrius

Agrius used 7zip to archive extracted data in preparation for exfiltration.

GroupAkira

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

GroupAPT1

APT1 has used RAR to compress files before moving them outside of the victim network.

GroupAPT28

APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection.

GroupAPT3

APT3 has used tools to compress data before exfilling it.

GroupAPT33

APT33 has used WinRAR to compress data prior to exfil.

GroupAPT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data.

GroupAPT41

APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.

View all 39 groups examples

Software36

Used byProcedure example
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

Malwareccf32

ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files.

Toolcertutil

certutil may be used to Base64 encode collected data.

MalwareCORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

MalwareCrutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.

MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

View all 36 software examples

Campaigns11

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data.

CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

CampaignC0026

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

CampaignCutting Edge

During Cutting Edge, threat actors saved collected data to a tar archive.

CampaignFunnyDream

During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.

View all 11 campaigns examples

References4

  1. 7zip Homepage Open source
    I. Pavlov. (2019). 7-Zip. Retrieved February 20, 2020.
  2. WinRAR Homepage Open source
    A. Roshal. (2020). RARLAB. Retrieved February 20, 2020.
  3. WinZip Homepage Open source
    Corel Corporation. (2020). WinZip. Retrieved February 20, 2020.
  4. diantz.exe_lolbas Open source
    Living Off The Land Binaries, Scripts and Libraries (LOLBAS). (n.d.). Diantz.exe. Retrieved October 25, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.