Archive via Library

T1560.002

Sub-technique of T1560 Archive Collected Data.View on attack.mitre.org

About this technique

An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including Python rarfile , libzip , and zlib . Most libraries include functionality to encrypt and/or compress data.

Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. The libraries can be linked against when compiling, while the utilities require spawning a subshell, or a similar execution mechanism.

Detection rules0

Rules on DetectionCode tagged with T1560.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software13

Campaigns0

None recorded.

Procedure examples16

Groups3

Used byProcedure example
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server.

GroupShinyHunters

ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `.

GroupThreat Group-3390

Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration.

Software13

Used byProcedure example
MalwareBADFLICK

BADFLICK has compressed data using the aPLib compression library.

MalwareBBSRAT

BBSRAT can compress data with ZLIB prior to sending it back to the C2 server.

MalwareCardinal RAT

Cardinal RAT applies compression to C2 traffic using the ZLIB library.

MalwareDenis

Denis compressed collected data using zlib.

MalwareEpic

Epic compresses the collected data with bzip2 before sending it to the C2 server.

MalwareFoggyWeb

FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class.

MalwareFunnyDream

FunnyDream has compressed collected files with zLib.

MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

View all 13 software examples

References3

  1. PyPI RAR Open source
    mkz. (2020). rarfile 3.1. Retrieved February 20, 2020.
  2. Zlib Github Open source
    madler. (2017). zlib. Retrieved February 20, 2020.
  3. libzip Open source
    D. Baron, T. Klausner. (2020). libzip. Retrieved February 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.