ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1560.001
Archive via Utility
GroupEarth Lusca

Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration.

T1560.001
Archive via Utility
GroupSowbug

Sowbug extracted documents and bundled them into a RAR archive.

T1560.001
Archive via Utility
GroupCopyKittens

CopyKittens uses ZPP, a .NET console program, to compress files with ZIP.

T1560.001
Archive via Utility
GroupWizard Spider

Wizard Spider has archived data into ZIP files on compromised machines.

T1560.001
Archive via Utility
GroupVOID MANTICORE

VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration.

T1560.001
Archive via Utility
GroupPlay

Play has used WinRAR to compress files prior to exfiltration.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1560.001
Archive via Utility
GroupAPT33

APT33 has used WinRAR to compress data prior to exfil.

T1560.001
Archive via Utility
GroupFIN8

FIN8 has used RAR to compress collected data before exfiltration.

T1560.001
Archive via Utility
GroupFIN13

FIN13 has compressed the dump output of compromised credentials with a 7zip binary.

T1560.001
Archive via Utility
MalwareWindTail

WindTail has the ability to use the macOS built-in zip utility to archive files.

T1560.001
Archive via Utility
MalwareInvisibleFerret

InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration.

T1560.001
Archive via Utility
MalwareTONESHELL

TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives.

T1560.001
Archive via Utility
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

T1560.001
Archive via Utility
MalwareiKitten

iKitten will zip up the /Library/Keychains directory before exfiltrating it.

T1560.001
Archive via Utility
MalwareTurian

Turian can use WinRAR to create a password-protected archive for files of interest.

T1560.001
Archive via Utility
MalwarePUBLOAD

PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration.

T1560.001
Archive via Utility
MalwareInvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.

T1560.001
Archive via Utility
MalwareOkrum

Okrum was seen using a RAR archiver tool to compress/decompress data.

T1560.001
Archive via Utility
MalwarePowerShower

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.

T1560.001
Archive via Utility
MalwarePUNCHBUGGY

PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil.

T1560.001
Archive via Utility
MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

T1560.001
Archive via Utility
MalwareDustySky

DustySky can compress files via RAR while staging data to be exfiltrated.

T1560.001
Archive via Utility
MalwareSagerunex

Sagerunex has archived collected materials in RAR format.

T1560.001
Archive via Utility
MalwareGlassWorm

GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`.

T1560.001
Archive via Utility
MalwareCORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

T1560.001
Archive via Utility
MalwareMicropsia

Micropsia creates a RAR archive based on collected files on the victim's machine.

T1560.001
Archive via Utility
MalwareOopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.

T1560.001
Archive via Utility
MalwareCrutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.

T1560.001
Archive via Utility
Malwareccf32

ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files.

T1560.001
Archive via Utility
MalwareSampleCheck5000

SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration.

T1560.001
Archive via Utility
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility
MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

T1560.001
Archive via Utility
MalwareRamsay

Ramsay can compress and archive collected files using WinRAR.

T1560.001
Archive via Utility
MalwareLAMEHUG

LAMEHUG can xcopy for file collection on targeted systems.

T1560.001
Archive via Utility
MalwarePoetRAT

PoetRAT has the ability to compress files with zip.

T1560.001
Archive via Utility
MalwareIceApple

IceApple can encrypt and compress files using Gzip prior to exfiltration.

T1560.001
Archive via Utility
MalwareLunarWeb

LunarWeb can create a ZIP archive with specified files and directories.

T1560.001
Archive via Utility
MalwareOctopus

Octopus has compressed data before exfiltrating it using a tool called Abbrevia.

T1560.001
Archive via Utility
Toolcertutil

certutil may be used to Base64 encode collected data.

T1560.001
Archive via Utility
ToolPoshC2

PoshC2 contains a module for compressing data using ZIP.

T1560.001
Archive via Utility
ToolRclone

Rclone can compress files using `gzip` prior to exfiltration.

T1560.001
Archive via Utility
ToolRemcos

Remcos can zip files and folders for upload.

T1560.001
Archive via Utility
ToolPupy

Pupy can compress data with Zip before sending it over C2.

T1560.001
Archive via Utility
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration.

T1560.001
Archive via Utility
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration.

T1560.002
Archive via Library
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server.

T1560.002
Archive via Library
GroupThreat Group-3390

Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration.

T1560.002
Archive via Library
MalwareZLib

The ZLib backdoor compresses communications using the standard Zlib compression library.

T1560.002
Archive via Library
MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.