Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560 Archive Collected Data |
MalwareXCSSET | XCSSET will compress entire |
| T1560 Archive Collected Data |
MalwareAgent Tesla | Agent Tesla can encrypt data with 3DES before sending it over to a C2 server. |
| T1560 Archive Collected Data |
MalwareRemexi | Remexi encrypts and adds all gathered browser data into files for upload to C2. |
| T1560 Archive Collected Data |
MalwareLizar | Lizar has encrypted data before sending it to the server. |
| T1560 Archive Collected Data |
MalwareDtrack | Dtrack packs collected data into a password protected archive. |
| T1560 Archive Collected Data |
MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| T1560 Archive Collected Data |
ToolBloodHound | BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| T1560 Archive Collected Data |
ToolShimRatReporter | ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2. |
| T1560 Archive Collected Data |
ToolEmpire | Empire can ZIP directories on the target system. |
| T1560 Archive Collected Data |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures. |
| T1560.001 Archive via Utility |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
| T1560.001 Archive via Utility |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration. |
| T1560.001 Archive via Utility |
CampaignCutting Edge | During Cutting Edge, threat actors saved collected data to a tar archive. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1560.001 Archive via Utility |
CampaignFunnyDream | During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive. |
| T1560.001 Archive via Utility |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities ( |
| T1560.001 Archive via Utility |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignOperation Wocao | During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignC0026 | During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
| T1560.001 Archive via Utility |
GroupGALLIUM | GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT3 | APT3 has used tools to compress data before exfilling it. |
| T1560.001 Archive via Utility |
GroupKimsuky | Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration. |
| T1560.001 Archive via Utility |
GroupVolt Typhoon | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip. |
| T1560.001 Archive via Utility |
GroupAPT41 | APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration. |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1560.001 Archive via Utility |
GroupHAFNIUM | HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| T1560.001 Archive via Utility |
GroupMuddyWater | MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded. |
| T1560.001 Archive via Utility |
GroupGallmaker | Gallmaker has used WinZip, likely to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupMustang Panda | Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT39 | APT39 has used WinRAR and 7-Zip to compress an archive stolen data. |
| T1560.001 Archive via Utility |
GroupUNC3886 | UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems. |
| T1560.001 Archive via Utility |
GroupAkira | Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupSea Turtle | Sea Turtle used the tar utility to create a local archive of email data on a victim system. |
| T1560.001 Archive via Utility |
GroupAquatic Panda | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupKe3chang | Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT1 | APT1 has used RAR to compress files before moving them outside of the victim network. |
| T1560.001 Archive via Utility |
GroupTurla | Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration. |
| T1560.001 Archive via Utility |
GroupRedCurl | RedCurl has downloaded 7-Zip to decompress password protected archives. |
| T1560.001 Archive via Utility |
GroupLotus Blossom | Lotus Blossom has used WinRAR for compressing data in RAR format. |
| T1560.001 Archive via Utility |
GroupChimera | Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupBRONZE BUTLER | BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupToddyCat | ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAgrius | Agrius used 7zip to archive extracted data in preparation for exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT28 | APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection. |
| T1560.001 Archive via Utility |
GroupAPT5 | APT5 has used the JAR/ZIP file format for exfiltrated files. |
| T1560.001 Archive via Utility |
GroupFox Kitten | Fox Kitten has used 7-Zip to archive data. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.