ATT&CK · T1573
Encrypted Channel
Tactics: command-and-control
About
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗
Used by actors
4 known groups
Software
11 malware/tools implement this
gh0st RATNETWIREEmotetCryptoisticChaesRCSessionLizarPowerLessMacMaPowGoopGomir
Corpus indicators tagged with this technique
2,309 indicators in the corpus carry T1573.
Showing the top 30 by severity of 2,309.