Sub-technique of T1560 Archive Collected Data.View on attack.mitre.org
An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.
Rules on DetectionCode tagged with T1560.003.
| Used by | Procedure example |
|---|---|
| GroupCopyKittens | CopyKittens encrypts data with a substitute cipher prior to exfiltration. |
| GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
| GroupKimsuky | Kimsuky has used RC4 encryption before exfil. |
| GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| GroupLotus Blossom | Lotus Blossom has used custom tools to compress and archive data on victim systems. |
| GroupMustang Panda | Mustang Panda has encrypted documents with RC4 prior to exfiltration. |
| GroupUNC3886 | UNC3886 has XOR encrypted and Gzip compressed captured credentials. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
| MalwareAgent.btz | Agent.btz saves system information into an XML file that is then XOR-encoded. |
| MalwareAttor | Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers. |
| MalwareBLUELIGHT | BLUELIGHT has encoded data into a binary blob using XOR. |
| MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| MalwareFLASHFLOOD | FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23. |
| MalwareFoggyWeb | FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file. |
| MalwareFrameworkPOS | FrameworkPOS can XOR credit card information before exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.