Archive Collected Data

T1560

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.

Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.

Detection rules22

Rules on DetectionCode tagged with T1560 or one of its sub-techniques.

Sigma13

Splunk9

RuleTypeRiskData sourceTechnique
7zip CommandLine To SMB Share PathHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1560.001
Anomalous usage of 7zipAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1560.001
Detect Certipy File ModificationsTTPNULLSysmon EventID 11T1560
Detect Renamed 7-ZipHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1560.001
Detect Renamed WinRARHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1560.001
IcedID Exfiltrated Archived File CreationHuntingNULLSysmon EventID 11T1560.001
Windows Archive Collected Data via PowershellAnomalyNULLPowershell Script Block Logging 4104T1560
Windows Archive Collected Data via RarAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1560.001
Windows Archived Collected Data In TEMP FolderAnomalyNULLSysmon EventID 11T1560

Sub-techniques3

IDNameExamples
T1560.001Archive via Utility86
T1560.002Archive via Library16
T1560.003Archive via Custom Method39

Groups13

Software44

Show 20 more

Campaigns0

None recorded.

Procedure examples57

Groups13

Used byProcedure example
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

GroupAxiom

Axiom has compressed and encrypted data prior to exfiltration.

GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

GroupEmber Bear

Ember Bear has compressed collected data prior to exfiltration.

GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

GroupKe3chang

The Ke3chang group has been known to compress data before exfiltration.

View all 13 groups examples

Software44

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

ToolBloodHound

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

MalwareBLUELIGHT

BLUELIGHT can zip files before exfiltration.

MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

View all 44 software examples

References1

  1. DOJ GRU Indictment Jul 2018 Open source
    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.