Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560 Archive Collected Data |
MalwareSpica | Spica can archive collected documents for exfiltration. |
| T1560 Archive Collected Data |
MalwareKONNI | KONNI has encrypted data and files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareBLUELIGHT | BLUELIGHT can zip files before exfiltration. |
| T1560 Archive Collected Data |
MalwareWellMail | WellMail can archive files on the compromised host. |
| T1560 Archive Collected Data |
MalwareZebrocy | Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. |
| T1560 Archive Collected Data |
MalwareCadelspy | Cadelspy has the ability to compress stolen data into a .cab file. |
| T1560 Archive Collected Data |
MalwareRaccoon Stealer | Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560 Archive Collected Data |
MalwareGold Dragon | Gold Dragon encrypts data using Base64 before being sent to the command and control server. |
| T1560 Archive Collected Data |
MalwarePillowmint | Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64. |
| T1560 Archive Collected Data |
MalwareProton | Proton zips up files before exfiltrating them. |
| T1560 Archive Collected Data |
MalwareKessel | Kessel can RC4-encrypt credentials before sending to the C2. |
| T1560 Archive Collected Data |
MalwareFELIXROOT | FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server. |
| T1560 Archive Collected Data |
MalwareTroll Stealer | Troll Stealer compresses stolen data prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareXCSSET | XCSSET will compress entire |
| T1560 Archive Collected Data |
MalwareAgent Tesla | Agent Tesla can encrypt data with 3DES before sending it over to a C2 server. |
| T1560 Archive Collected Data |
MalwareRemexi | Remexi encrypts and adds all gathered browser data into files for upload to C2. |
| T1560 Archive Collected Data |
MalwareLizar | Lizar has encrypted data before sending it to the server. |
| T1560 Archive Collected Data |
MalwareDtrack | Dtrack packs collected data into a password protected archive. |
| T1560 Archive Collected Data |
MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| T1560 Archive Collected Data |
ToolBloodHound | BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| T1560 Archive Collected Data |
ToolShimRatReporter | ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2. |
| T1560 Archive Collected Data |
ToolEmpire | Empire can ZIP directories on the target system. |
| T1560 Archive Collected Data |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures. |
| T1560.001 Archive via Utility |
MalwareWindTail | WindTail has the ability to use the macOS built-in zip utility to archive files. |
| T1560.001 Archive via Utility |
MalwareInvisibleFerret | InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1560.001 Archive via Utility |
MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| T1560.001 Archive via Utility |
MalwareiKitten | iKitten will zip up the /Library/Keychains directory before exfiltrating it. |
| T1560.001 Archive via Utility |
MalwareTurian | Turian can use WinRAR to create a password-protected archive for files of interest. |
| T1560.001 Archive via Utility |
MalwarePUBLOAD | PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareInvisiMole | InvisiMole uses WinRAR to compress data that is intended to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareOkrum | Okrum was seen using a RAR archiver tool to compress/decompress data. |
| T1560.001 Archive via Utility |
MalwarePowerShower | PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwarePUNCHBUGGY | PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil. |
| T1560.001 Archive via Utility |
MalwareBeaverTail | BeaverTail has collected and archived sensitive data in a zip file. |
| T1560.001 Archive via Utility |
MalwareDustySky | DustySky can compress files via RAR while staging data to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareSagerunex | Sagerunex has archived collected materials in RAR format. |
| T1560.001 Archive via Utility |
MalwareGlassWorm | GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`. |
| T1560.001 Archive via Utility |
MalwareCORALDECK | CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareMicropsia | Micropsia creates a RAR archive based on collected files on the victim's machine. |
| T1560.001 Archive via Utility |
MalwareOopsIE | OopsIE compresses collected files with GZipStream before sending them to its C2 server. |
| T1560.001 Archive via Utility |
MalwareCrutch | Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| T1560.001 Archive via Utility |
Malwareccf32 | ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files. |
| T1560.001 Archive via Utility |
MalwareSampleCheck5000 | SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration. |
| T1560.001 Archive via Utility |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560.001 Archive via Utility |
MalwareCalisto | Calisto uses the |
| T1560.001 Archive via Utility |
MalwareRamsay | Ramsay can compress and archive collected files using WinRAR. |
| T1560.001 Archive via Utility |
MalwareLAMEHUG | LAMEHUG can xcopy for file collection on targeted systems. |
| T1560.001 Archive via Utility |
MalwarePoetRAT | PoetRAT has the ability to compress files with zip. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.