Technique with 3 sub-techniques.View on attack.mitre.org
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.
Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.
Rules on DetectionCode tagged with T1560 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| 7zip CommandLine To SMB Share Path | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1560.001 |
| Anomalous usage of 7zip | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1560.001 |
| Detect Certipy File Modifications | TTP | NULL | Sysmon EventID 11 | T1560 |
| Detect Renamed 7-Zip | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1560.001 |
| Detect Renamed WinRAR | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1560.001 |
| IcedID Exfiltrated Archived File Creation | Hunting | NULL | Sysmon EventID 11 | T1560.001 |
| Windows Archive Collected Data via Powershell | Anomaly | NULL | Powershell Script Block Logging 4104 | T1560 |
| Windows Archive Collected Data via Rar | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1560.001 |
| Windows Archived Collected Data In TEMP Folder | Anomaly | NULL | Sysmon EventID 11 | T1560 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| GroupAxiom | Axiom has compressed and encrypted data prior to exfiltration. |
| GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| GroupEmber Bear | Ember Bear has compressed collected data prior to exfiltration. |
| GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
| GroupKe3chang | The Ke3chang group has been known to compress data before exfiltration. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| MalwareAgent Tesla | Agent Tesla can encrypt data with 3DES before sending it over to a C2 server. |
| MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| MalwareAria-body | Aria-body has used ZIP to compress data gathered on a compromised host. |
| MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
| ToolBloodHound | BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| MalwareBLUELIGHT | BLUELIGHT can zip files before exfiltration. |
| MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.