Archive Collected Data, Technique T1560 - Enterprise (original) (raw)
ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.[2]
Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.[3]
AppleSeed has compressed collected data before exfiltration.[4]
APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.[1]
APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.[5]
Aria-body has used ZIP to compress data gathered on a compromised host.[6]
Axiom has compressed and encrypted data prior to exfiltration.[7]
Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.[8]
BlackByte compressed data collected from victim environments prior to exfiltration.[9]
BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.[10][11]
BLUELIGHT can zip files before exfiltration.[12]
Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.[13]
Cadelspy has the ability to compress stolen data into a .cab file.[14]
Chrommme can encrypt and store on disk collected data before exfiltration.[15]
Daserf hides collected data in password-protected .rar archives.[16]
Dragonfly has compressed data into .zip files prior to exfiltration.[17]
Dtrack packs collected data into a password protected archive.[18]
Ember Bear has compressed collected data prior to exfiltration.[19]
Empire can ZIP directories on the target system.[20]
Epic encrypts collected data using a public key framework before sending it over the C2 channel.[21] Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.[22]
Exaramel for Windows automatically encrypts files before sending them to the C2 server.[23]
FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.[24]
Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.[25]
Gold Dragon encrypts data using Base64 before being sent to the command and control server.[26]
JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices.[27]
The Ke3chang group has been known to compress data before exfiltration.[28]
Kessel can RC4-encrypt credentials before sending to the C2.[29]
KONNI has encrypted data and files prior to exfiltration.[30]
Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. [31][32][33]
Leviathan has archived victim's data prior to exfiltration.[34]
LightNeuron contains a function to encrypt and store emails that it collects.[35]
Lizar has encrypted data before sending it to the server.[36]
LoFiSe can collect files into password-protected ZIP-archives for exfiltration.[37]
LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC
and the initialization vector 91A4E6F6D51DAEE773A8F00279792578.[38]
LuminousMoth has manually archived stolen files from victim machines before exfiltration.[39]
Lurid can compress data before sending it.[40]
Machete stores zipped files with profile data from installed web browsers.[41]
menuPass has encrypted files and information before exfiltration.[42][43]
MuddyViper has archived collected web browser data into a file named CacheDump.zip.[38]
NETWIRE has the ability to compress archived screenshots.[44]
Patchwork encrypted the collected files' path with AES and then encoded them with base64.[45]
Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.[46]
PowerLess can encrypt browser database files prior to exfiltration.[47]
After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish.[48]
Proton zips up files before exfiltrating them.[49]
Raccoon Stealer archives collected system information in a text f ile, System info.txt, prior to exfiltration.[50]
Remexi encrypts and adds all gathered browser data into files for upload to C2.[51]
RunningRAT contains code to compress files.[26]
ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.[52]
Spica can archive collected documents for exfiltration.[53]
TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.[54]
Troll Stealer compresses stolen data prior to exfiltration.[55]
VERMIN encrypts the collected files using 3-DES.[56]
WellMail can archive files on the compromised host.[57]
XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.[58]
Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. [59][60][61]