ATT&CK · T1560
Archive Collected Data
Tactics: collection
About
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.
Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
13 known groups
Software
43 malware/tools implement this
LuridADVSTORESHELLEpicBackdoor.OldreaPrikormkaDaserfNETWIREGold DragonZebrocyRunningRATVERMINFELIXROOTProtonAgent TeslaExaramel for WindowsKONNIEmpireRemexiLightNeuronMacheteShimRatReporterCadelspyAria-bodyKesselWellMailPillowmintBloodHoundDtrackTAINTEDSCRIBEAppleSeedBLUELIGHTXCSSETChrommmeLizarPowerLessBumblebeeLoFiSeSpicaRaccoon StealerTroll StealerJumbledPathMuddyViperLP-Notes
Corpus indicators tagged with this technique
51 indicators in the corpus carry T1560.
Showing the top 30 by severity of 51.