Archive via Custom Method

T1560.003

Sub-technique of T1560 Archive Collected Data.View on attack.mitre.org

About this technique

An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.

Detection rules0

Rules on DetectionCode tagged with T1560.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups7

Software31

Show 7 more

Campaigns1

Procedure examples39

Groups7

Used byProcedure example
GroupCopyKittens

CopyKittens encrypts data with a substitute cipher prior to exfiltration.

GroupFIN6

FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation.

GroupKimsuky

Kimsuky has used RC4 encryption before exfil.

GroupLazarus Group

A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration.

GroupLotus Blossom

Lotus Blossom has used custom tools to compress and archive data on victim systems.

GroupMustang Panda

Mustang Panda has encrypted documents with RC4 prior to exfiltration.

GroupUNC3886

UNC3886 has XOR encrypted and Gzip compressed captured credentials.

Software31

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.

MalwareAgent.btz

Agent.btz saves system information into an XML file that is then XOR-encoded.

MalwareAttor

Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers.

MalwareBLUELIGHT

BLUELIGHT has encoded data into a binary blob using XOR.

MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

MalwareFLASHFLOOD

FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23.

MalwareFoggyWeb

FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file.

MalwareFrameworkPOS

FrameworkPOS can XOR credit card information before exfiltration.

View all 31 software examples

Campaigns1

Used byProcedure example
CampaignC0017

During C0017, APT41 hex-encoded PII data prior to exfiltration.

References1

  1. ESET Sednit Part 2 Open source
    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.