Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560 Archive Collected Data |
GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| T1560 Archive Collected Data |
GroupPatchwork | Patchwork encrypted the collected files' path with AES and then encoded them with base64. |
| T1560 Archive Collected Data |
GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| T1560 Archive Collected Data |
GroupmenuPass | menuPass has encrypted files and information before exfiltration. |
| T1560 Archive Collected Data |
GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| T1560 Archive Collected Data |
GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
| T1560 Archive Collected Data |
GroupKe3chang | The Ke3chang group has been known to compress data before exfiltration. |
| T1560 Archive Collected Data |
GroupLeviathan | Leviathan has archived victim's data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupAxiom | Axiom has compressed and encrypted data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupEmber Bear | Ember Bear has compressed collected data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupLuminousMoth | LuminousMoth has manually archived stolen files from victim machines before exfiltration. |
| T1560 Archive Collected Data |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1560 Archive Collected Data |
GroupLazarus Group | Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.