ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1560.001
Archive via Utility
MalwareIceApple

IceApple can encrypt and compress files using Gzip prior to exfiltration.

T1560.001
Archive via Utility
MalwareLunarWeb

LunarWeb can create a ZIP archive with specified files and directories.

T1560.001
Archive via Utility
MalwareOctopus

Octopus has compressed data before exfiltrating it using a tool called Abbrevia.

T1560.001
Archive via Utility
Toolcertutil

certutil may be used to Base64 encode collected data.

T1560.001
Archive via Utility
ToolPoshC2

PoshC2 contains a module for compressing data using ZIP.

T1560.001
Archive via Utility
ToolRclone

Rclone can compress files using `gzip` prior to exfiltration.

T1560.001
Archive via Utility
ToolRemcos

Remcos can zip files and folders for upload.

T1560.001
Archive via Utility
ToolPupy

Pupy can compress data with Zip before sending it over C2.

T1560.001
Archive via Utility
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration.

T1560.001
Archive via Utility
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration.

T1560.002
Archive via Library
MalwareZLib

The ZLib backdoor compresses communications using the standard Zlib compression library.

T1560.002
Archive via Library
MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

T1560.002
Archive via Library
MalwareBBSRAT

BBSRAT can compress data with ZLIB prior to sending it back to the C2 server.

T1560.002
Archive via Library
MalwareSeaDuke

SeaDuke compressed data with zlib prior to sending it over C2.

T1560.002
Archive via Library
MalwareEpic

Epic compresses the collected data with bzip2 before sending it to the C2 server.

T1560.002
Archive via Library
MalwareFoggyWeb

FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class.

T1560.002
Archive via Library
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server.

T1560.002
Archive via Library
MalwareTajMahal

TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files.

T1560.002
Archive via Library
MalwareCardinal RAT

Cardinal RAT applies compression to C2 traffic using the ZLIB library.

T1560.002
Archive via Library
MalwareFunnyDream

FunnyDream has compressed collected files with zLib.

T1560.002
Archive via Library
MalwareLunarWeb

LunarWeb can zlib-compress data prior to exfiltration.

T1560.002
Archive via Library
MalwareDenis

Denis compressed collected data using zlib.

T1560.002
Archive via Library
MalwareBADFLICK

BADFLICK has compressed data using the aPLib compression library.

T1560.003
Archive via Custom Method
MalwareStuxnet

Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys.

T1560.003
Archive via Custom Method
MalwareHAWKBALL

HAWKBALL has encrypted data with XOR before sending it over the C2 channel.

T1560.003
Archive via Custom Method
MalwareFrameworkPOS

FrameworkPOS can XOR credit card information before exfiltration.

T1560.003
Archive via Custom Method
MalwareStrongPity

StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme.

T1560.003
Archive via Custom Method
MalwareNETWIRE

NETWIRE has used a custom encryption algorithm to encrypt collected data.

T1560.003
Archive via Custom Method
MalwareMachete

Machete's collected data is encrypted with AES before exfiltration.

T1560.003
Archive via Custom Method
MalwareSquirrelwaffle

Squirrelwaffle has encrypted collected data using a XOR-based algorithm.

T1560.003
Archive via Custom Method
MalwareAgent.btz

Agent.btz saves system information into an XML file that is then XOR-encoded.

T1560.003
Archive via Custom Method
MalwareSombRAT

SombRAT has encrypted collected data with AES-256 using a hardcoded key.

T1560.003
Archive via Custom Method
MalwareFLASHFLOOD

FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23.

T1560.003
Archive via Custom Method
MalwareInvisiMole

InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration.

T1560.003
Archive via Custom Method
MalwareOkrum

Okrum has used a custom implementation of AES encryption to encrypt collected data.

T1560.003
Archive via Custom Method
MalwareRising Sun

Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareReaver

Reaver encrypts collected data with an incremental XOR key prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareFoggyWeb

FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file.

T1560.003
Archive via Custom Method
MalwareT9000

T9000 encrypts collected data using a single byte XOR key.

T1560.003
Archive via Custom Method
MalwareSPACESHIP

Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23.

T1560.003
Archive via Custom Method
MalwareBLUELIGHT

BLUELIGHT has encoded data into a binary blob using XOR.

T1560.003
Archive via Custom Method
MalwareOopsIE

OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server.

T1560.003
Archive via Custom Method
MalwareAttor

Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers.

T1560.003
Archive via Custom Method
MalwareRawPOS

RawPOS encodes credit card data it collected from the victim with XOR.

T1560.003
Archive via Custom Method
MalwareMESSAGETAP

MESSAGETAP has XOR-encrypted and stored contents of SMS messages that matched its target list.

T1560.003
Archive via Custom Method
MalwareSUGARDUMP

SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64.

T1560.003
Archive via Custom Method
MalwareOwaAuth

OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file.

T1560.003
Archive via Custom Method
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk.

T1560.003
Archive via Custom Method
MalwareRGDoor

RGDoor encrypts files with XOR before sending them back to the C2 server.

T1560.003
Archive via Custom Method
MalwareRamsay

Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.