Symmetric Cryptography

T1573.001

Sub-technique of T1573 Encrypted Channel.View on attack.mitre.org

About this technique

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.

Detection rules0

Rules on DetectionCode tagged with T1573.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups14

Software167

Show 143 more

Campaigns4

Procedure examples185

Groups14

Used byProcedure example
GroupAPT28

APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications.

GroupAPT33

APT33 has used AES for encryption of command and control traffic.

GroupBRONZE BUTLER

BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server.

GroupContagious Interview

Contagious Interview has encrypted C2 traffic using RC4.

GroupDarkhotel

Darkhotel has used AES-256 and 3DES for C2 communications.

GroupHigaisa

Higaisa used AES-128 to encrypt C2 traffic.

GroupInception

Inception has encrypted network communications with AES.

GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

View all 14 groups examples

Software167

Used byProcedure example
Malware3PARA RAT

3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails

Malware4H RAT

4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE.

MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with 3DES.

MalwareAttor

Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key.

MalwareAzorult

Azorult can encrypt C2 traffic using XOR.

MalwareBADCALL

BADCALL encrypts C2 traffic using an XOR/ADD cipher.

MalwareBADNEWS

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.

MalwareBandook

Bandook has used AES encryption for C2 communication.

View all 167 software examples

Campaigns4

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL communication module supports three commands to conduct the following actions: send implant data, execute shellcode, and terminate itself.

CampaignFrankenstein

During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server.

CampaignRedPenguin

During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.