Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.001 Archive via Utility |
GroupEarth Lusca | Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupSowbug | Sowbug extracted documents and bundled them into a RAR archive. |
| T1560.001 Archive via Utility |
GroupCopyKittens | CopyKittens uses ZPP, a .NET console program, to compress files with ZIP. |
| T1560.001 Archive via Utility |
GroupWizard Spider | Wizard Spider has archived data into ZIP files on compromised machines. |
| T1560.001 Archive via Utility |
GroupVOID MANTICORE | VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupPlay | Play has used WinRAR to compress files prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupMagic Hound | Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders. |
| T1560.001 Archive via Utility |
GroupAPT33 | APT33 has used WinRAR to compress data prior to exfil. |
| T1560.001 Archive via Utility |
GroupFIN8 | FIN8 has used RAR to compress collected data before exfiltration. |
| T1560.001 Archive via Utility |
GroupFIN13 | FIN13 has compressed the dump output of compromised credentials with a 7zip binary. |
| T1560.001 Archive via Utility |
MalwareWindTail | WindTail has the ability to use the macOS built-in zip utility to archive files. |
| T1560.001 Archive via Utility |
MalwareInvisibleFerret | InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1560.001 Archive via Utility |
MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| T1560.001 Archive via Utility |
MalwareiKitten | iKitten will zip up the /Library/Keychains directory before exfiltrating it. |
| T1560.001 Archive via Utility |
MalwareTurian | Turian can use WinRAR to create a password-protected archive for files of interest. |
| T1560.001 Archive via Utility |
MalwarePUBLOAD | PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareInvisiMole | InvisiMole uses WinRAR to compress data that is intended to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareOkrum | Okrum was seen using a RAR archiver tool to compress/decompress data. |
| T1560.001 Archive via Utility |
MalwarePowerShower | PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwarePUNCHBUGGY | PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil. |
| T1560.001 Archive via Utility |
MalwareBeaverTail | BeaverTail has collected and archived sensitive data in a zip file. |
| T1560.001 Archive via Utility |
MalwareDustySky | DustySky can compress files via RAR while staging data to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareSagerunex | Sagerunex has archived collected materials in RAR format. |
| T1560.001 Archive via Utility |
MalwareGlassWorm | GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`. |
| T1560.001 Archive via Utility |
MalwareCORALDECK | CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
| T1560.001 Archive via Utility |
MalwareMicropsia | Micropsia creates a RAR archive based on collected files on the victim's machine. |
| T1560.001 Archive via Utility |
MalwareOopsIE | OopsIE compresses collected files with GZipStream before sending them to its C2 server. |
| T1560.001 Archive via Utility |
MalwareCrutch | Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| T1560.001 Archive via Utility |
Malwareccf32 | ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files. |
| T1560.001 Archive via Utility |
MalwareSampleCheck5000 | SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration. |
| T1560.001 Archive via Utility |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560.001 Archive via Utility |
MalwareCalisto | Calisto uses the |
| T1560.001 Archive via Utility |
MalwareRamsay | Ramsay can compress and archive collected files using WinRAR. |
| T1560.001 Archive via Utility |
MalwareLAMEHUG | LAMEHUG can xcopy for file collection on targeted systems. |
| T1560.001 Archive via Utility |
MalwarePoetRAT | PoetRAT has the ability to compress files with zip. |
| T1560.001 Archive via Utility |
MalwareIceApple | IceApple can encrypt and compress files using Gzip prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareLunarWeb | LunarWeb can create a ZIP archive with specified files and directories. |
| T1560.001 Archive via Utility |
MalwareOctopus | Octopus has compressed data before exfiltrating it using a tool called Abbrevia. |
| T1560.001 Archive via Utility |
Toolcertutil | certutil may be used to Base64 encode collected data. |
| T1560.001 Archive via Utility |
ToolPoshC2 | PoshC2 contains a module for compressing data using ZIP. |
| T1560.001 Archive via Utility |
ToolRclone | Rclone can compress files using `gzip` prior to exfiltration. |
| T1560.001 Archive via Utility |
ToolRemcos | Remcos can zip files and folders for upload. |
| T1560.001 Archive via Utility |
ToolPupy | Pupy can compress data with Zip before sending it over C2. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1560.001 Archive via Utility |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration. |
| T1560.002 Archive via Library |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server. |
| T1560.002 Archive via Library |
GroupThreat Group-3390 | Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration. |
| T1560.002 Archive via Library |
MalwareZLib | The ZLib backdoor compresses communications using the standard Zlib compression library. |
| T1560.002 Archive via Library |
MalwareInvisiMole | InvisiMole can use zlib to compress and decompress data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.