Sub-technique of T1573 Encrypted Channel.View on attack.mitre.org
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Rules on DetectionCode tagged with T1573.001.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications. |
| GroupAPT33 | APT33 has used AES for encryption of command and control traffic. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server. |
| GroupContagious Interview | Contagious Interview has encrypted C2 traffic using RC4. |
| GroupDarkhotel | Darkhotel has used AES-256 and 3DES for C2 communications. |
| GroupHigaisa | Higaisa used AES-128 to encrypt C2 traffic. |
| GroupInception | Inception has encrypted network communications with AES. |
| GroupLazarus Group | Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic. |
| Used by | Procedure example |
|---|---|
| Malware3PARA RAT | 3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails |
| Malware4H RAT | 4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE. |
| MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with 3DES. |
| MalwareAttor | Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key. |
| MalwareAzorult | Azorult can encrypt C2 traffic using XOR. |
| MalwareBADCALL | BADCALL encrypts C2 traffic using an XOR/ADD cipher. |
| MalwareBADNEWS | BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23. |
| MalwareBandook | Bandook has used AES encryption for C2 communication. |
View all 167 software examples
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL communication module supports three commands to conduct the following actions: send implant data, execute shellcode, and terminate itself. |
| CampaignFrankenstein | During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server. |
| CampaignRedPenguin | During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.