Sub-technique of T1560 Archive Collected Data.View on attack.mitre.org
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.
Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.
On Windows, diantz or makecab may be used to package collected files into a cabinet (.cab) file. diantz may also be used to download and compress files from remote locations (i.e. Remote Data Staging). xcopy on Windows can copy files and directories with a variety of options. Additionally, adversaries may use certutil to Base64 encode collected data before exfiltration.
Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.
Rules on DetectionCode tagged with T1560.001.
| Rule | Level | Log source |
|---|---|---|
| Rar Usage with Password and Compression Level | high | windows / process_creation |
| Suspicious Manipulation Of Default Accounts Via Net.EXE | high | windows / process_creation |
| 7Zip Compressing Dump Files | medium | windows / process_creation |
| Compress Data and Lock With Password for Exfiltration With 7-ZIP | medium | windows / process_creation |
| Compress Data and Lock With Password for Exfiltration With WINZIP | medium | windows / process_creation |
| Disk Image Mounting Via Hdiutil - MacOS | medium | macos / process_creation |
| Winrar Compressing Dump Files | medium | windows / process_creation |
| WinRAR Execution in Non-Standard Folder | medium | windows / process_creation |
| Cisco Stage Data | low | cisco / NULL |
| Compressed File Creation Via Tar.EXE | low | windows / process_creation |
| Compressed File Extraction Via Tar.EXE | low | windows / process_creation |
| Data Compressed | low | linux / NULL |
| Files Added To An Archive Using Rar.EXE | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| 7zip CommandLine To SMB Share Path | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Anomalous usage of 7zip | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Renamed 7-Zip | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Renamed WinRAR | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| IcedID Exfiltrated Archived File Creation | Hunting | NULL | Sysmon EventID 11 |
| Windows Archive Collected Data via Rar | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used 7zip to archive extracted data in preparation for exfiltration. |
| GroupAkira | Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| GroupAPT1 | APT1 has used RAR to compress files before moving them outside of the victim network. |
| GroupAPT28 | APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection. |
| GroupAPT3 | APT3 has used tools to compress data before exfilling it. |
| GroupAPT33 | APT33 has used WinRAR to compress data prior to exfil. |
| GroupAPT39 | APT39 has used WinRAR and 7-Zip to compress an archive stolen data. |
| GroupAPT41 | APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration. |
| Used by | Procedure example |
|---|---|
| MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| MalwareBeaverTail | BeaverTail has collected and archived sensitive data in a zip file. |
| MalwareCalisto | Calisto uses the |
| Malwareccf32 | ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files. |
| Toolcertutil | certutil may be used to Base64 encode collected data. |
| MalwareCORALDECK | CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
| MalwareCrutch | Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities ( |
| CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| CampaignC0026 | During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
| CampaignCutting Edge | During Cutting Edge, threat actors saved collected data to a tar archive. |
| CampaignFunnyDream | During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.