FORENSIA

ATT&CK · T1560.003 · sub-technique

Archive via Custom Method

Tactics: collection

About

An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.

Platforms: Linux, macOS, WindowsParent: T1560 Archive Collected DataMITRE ATT&CK ↗

Used by actors

7 known groups

Software

31 malware/tools implement this

SPACESHIPFLASHFLOODDuquADVSTORESHELLOwaAuthAgent.btzT9000RawPOSReaverNETWIRERGDoorInvisiMoleOopsIEOSX_OCEANLOTUS.DHAWKBALLMacheteAttorOkrumMESSAGETAPRising SunRamsayStrongPityFrameworkPOSStuxnetSombRATBLUELIGHTFoggyWebSquirrelwaffleSUGARDUMPFunnyDreammetaMain

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1560.003.

No corpus indicators are tagged with this technique yet.