Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Rules on DetectionCode tagged with T1573 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Activity from Anonymous IP Addresses | medium | m365 / NULL | T1573 |
| Activity from Infrequent Country | medium | m365 / NULL | T1573 |
| Activity from Suspicious IP Addresses | medium | m365 / NULL | T1573 |
| Suspicious SSL Connection | low | windows / ps_script | T1573 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | TTP | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1573.002 |
| Cisco Secure Firewall - High EVE Threat Confidence | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1573.002 |
| Cisco Secure Firewall - Intrusion Events by Threat Activity | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1573.002 |
| Cisco Secure Firewall - Lumma Stealer Download Attempt | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1573.002 |
| Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1573.002 |
| SSL Certificates with Punycode | Hunting | NULL | T1573 | |
| Zeek x509 Certificate with Punycode | Hunting | NULL | T1573 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has used multiple layers of encryption within malware to protect C2 communication. |
| GroupBITTER | BITTER has encrypted their C2 communications. |
| GroupMagic Hound | Magic Hound has used an encrypted http proxy in C2 communications. |
| GroupTropic Trooper | Tropic Trooper has encrypted traffic with the C2 to prevent network detection. |
| Used by | Procedure example |
|---|---|
| MalwareChaes | Chaes has used encryption for its C2 channel. |
| MalwareCryptoistic | Cryptoistic can engage in encrypted communications with C2. |
| MalwareEmotet | Emotet has encrypted data before sending to the C2 server. |
| Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| MalwareGomir | Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| MalwareLizar | Lizar can support encrypted communications between the client and server. |
| MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| Used by | Procedure example |
|---|---|
| CampaignKV Botnet Activity | KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation. |
| CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.