ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1560
Archive Collected Data
MalwareXCSSET

XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.

T1560
Archive Collected Data
MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

T1560
Archive Collected Data
MalwareRemexi

Remexi encrypts and adds all gathered browser data into files for upload to C2.

T1560
Archive Collected Data
MalwareLizar

Lizar has encrypted data before sending it to the server.

T1560
Archive Collected Data
MalwareDtrack

Dtrack packs collected data into a password protected archive.

T1560
Archive Collected Data
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

T1560
Archive Collected Data
ToolBloodHound

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

T1560
Archive Collected Data
ToolShimRatReporter

ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.

T1560
Archive Collected Data
ToolEmpire

Empire can ZIP directories on the target system.

T1560
Archive Collected Data
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures.

T1560.001
Archive via Utility
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.

T1560.001
Archive via Utility
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration.

T1560.001
Archive via Utility
CampaignCutting Edge

During Cutting Edge, threat actors saved collected data to a tar archive.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1560.001
Archive via Utility
CampaignFunnyDream

During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive.

T1560.001
Archive via Utility
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data.

T1560.001
Archive via Utility
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1560.001
Archive via Utility
CampaignOperation Wocao

During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration.

T1560.001
Archive via Utility
CampaignC0026

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

T1560.001
Archive via Utility
GroupGALLIUM

GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration.

T1560.001
Archive via Utility
GroupAPT3

APT3 has used tools to compress data before exfilling it.

T1560.001
Archive via Utility
GroupKimsuky

Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration.

T1560.001
Archive via Utility
GroupVolt Typhoon

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.

T1560.001
Archive via Utility
GroupAPT41

APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1560.001
Archive via Utility
GroupHAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.

T1560.001
Archive via Utility
GroupMuddyWater

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.

T1560.001
Archive via Utility
GroupGallmaker

Gallmaker has used WinZip, likely to archive data prior to exfiltration.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1560.001
Archive via Utility
GroupAPT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data.

T1560.001
Archive via Utility
GroupUNC3886

UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems.

T1560.001
Archive via Utility
GroupAkira

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

T1560.001
Archive via Utility
GroupSea Turtle

Sea Turtle used the tar utility to create a local archive of email data on a victim system.

T1560.001
Archive via Utility
GroupAquatic Panda

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.

T1560.001
Archive via Utility
GroupKe3chang

Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration.

T1560.001
Archive via Utility
GroupAPT1

APT1 has used RAR to compress files before moving them outside of the victim network.

T1560.001
Archive via Utility
GroupTurla

Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration.

T1560.001
Archive via Utility
GroupRedCurl

RedCurl has downloaded 7-Zip to decompress password protected archives.

T1560.001
Archive via Utility
GroupLotus Blossom

Lotus Blossom has used WinRAR for compressing data in RAR format.

T1560.001
Archive via Utility
GroupChimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1560.001
Archive via Utility
GroupBRONZE BUTLER

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.

T1560.001
Archive via Utility
GroupToddyCat

ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration.

T1560.001
Archive via Utility
GroupAgrius

Agrius used 7zip to archive extracted data in preparation for exfiltration.

T1560.001
Archive via Utility
GroupAPT28

APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection.

T1560.001
Archive via Utility
GroupAPT5

APT5 has used the JAR/ZIP file format for exfiltrated files.

T1560.001
Archive via Utility
GroupFox Kitten

Fox Kitten has used 7-Zip to archive data.

T1560.001
Archive via Utility
GroupINC Ransom

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.