Encrypted Channel

T1573

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Detection rules11

Rules on DetectionCode tagged with T1573 or one of its sub-techniques.

Sigma4

RuleLevelLog sourceTechnique
Activity from Anonymous IP Addressesmediumm365 / NULLT1573
Activity from Infrequent Countrymediumm365 / NULLT1573
Activity from Suspicious IP Addressesmediumm365 / NULLT1573
Suspicious SSL Connectionlowwindows / ps_scriptT1573

Splunk7

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Blacklisted SSL Certificate FingerprintTTPNULLCisco Secure Firewall Threat Defense Connection EventT1573.002
Cisco Secure Firewall - High EVE Threat ConfidenceAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1573.002
Cisco Secure Firewall - Intrusion Events by Threat ActivityAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1573.002
Cisco Secure Firewall - Lumma Stealer Download AttemptAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1573.002
Cisco Secure Firewall - Lumma Stealer Outbound Connection AttemptAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1573.002
SSL Certificates with PunycodeHuntingNULLT1573
Zeek x509 Certificate with PunycodeHuntingNULLT1573

Sub-techniques2

IDNameExamples
T1573.001Symmetric Cryptography185
T1573.002Asymmetric Cryptography97

Groups4

Software11

Campaigns2

Procedure examples17

Groups4

Used byProcedure example
GroupAPT29

APT29 has used multiple layers of encryption within malware to protect C2 communication.

GroupBITTER

BITTER has encrypted their C2 communications.

GroupMagic Hound

Magic Hound has used an encrypted http proxy in C2 communications.

GroupTropic Trooper

Tropic Trooper has encrypted traffic with the C2 to prevent network detection.

Software11

Used byProcedure example
MalwareChaes

Chaes has used encryption for its C2 channel.

MalwareCryptoistic

Cryptoistic can engage in encrypted communications with C2.

MalwareEmotet

Emotet has encrypted data before sending to the C2 server.

Malwaregh0st RAT

gh0st RAT has encrypted TCP communications to evade detection.

MalwareGomir

Gomir uses a custom encryption algorithm for content sent to command and control infrastructure.

MalwareLizar

Lizar can support encrypted communications between the client and server.

MalwareMacMa

MacMa has used TLS encryption to initialize a custom protocol for C2 communications.

MalwareNETWIRE

NETWIRE can encrypt C2 communications.

View all 11 software examples

Campaigns2

Used byProcedure example
CampaignKV Botnet Activity

KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation.

CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.