FORENSIA

ATT&CK · T1573

Encrypted Channel

Tactics: command-and-control

About

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

11 malware/tools implement this

gh0st RATNETWIREEmotetCryptoisticChaesRCSessionLizarPowerLessMacMaPowGoopGomir

Corpus indicators tagged with this technique

2,309 indicators in the corpus carry T1573.

IndicatorTypeFamilySevSrc
cve-2020-22658cve852
cve-2016-5681cve852
cve-2020-22653cve852
cve-2025-2492cve852
cve-2025-11837cve852
cve-2013-3307cve852
cve-2025-68670cve852
cve-2018-8007cve851
cve-2017-17215cve852
cve-2016-0638cvephishing851
cve-2024-1781cve851
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
7105caa6d4fd8a2c67523d385277528e556ae4f6hash802
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
82e579bd49d69845133c9aa8585f8bd26736437bhash802
7b361a6d0d42309d09ec9000b53712b3hash802
d35695f2366a43628231e73ffa83ca106306a8fahash802
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
f96bcd875836da89800912de1e557891697c7cf4hash802
6c6cbed6aad96564ed87094785be07a1hashphishing802
fe0161fb8a26a0bf4afad746c7ebf89499dcd3a7hash802
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
bd46890121106b43f0c01ab82629400chashcryptojacking802

Showing the top 30 by severity of 2,309.