FORENSIA

ATT&CK · T1573.002 · sub-technique

Asymmetric Cryptography

Tactics: command-and-control

About

Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver’s public key and the receiver decrypts the data with their private key. This ensures that only the intended recipient can read the encrypted data. Common public key encryption algorithms include RSA and ElGamal. For efficiency, many protocols (including SSL/TLS) use symmetric cryptography once a connection is established, but use asymmetric cryptography to establish or transmit a key. As such, these protocols are classified as Asymmetric Cryptography.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsParent: T1573 Encrypted ChannelMITRE ATT&CK ↗

Used by actors

11 known groups

Software

79 malware/tools implement this

BISCUITSykipotUroburosCHOPSTICKADVSTORESHELLHi-ZorTrojan.KaraganyXTunnelComRATPOSHSPYCobalt StrikeGazerVolgmerTorPupyadbupdPOWERSTATSKoadicZebrocyRemcosCarbonGreyEnergyEmpireWannaCryServHelperDridexMachetePoetRATAttorRising SunMetamorfoIcedIDStrongPityREvilWellMessWellMailGrandoreiroBazarPay2KeyPenquinGoldMaxDokiSombRATSodaMasterGrimAgentSliverKobalosTinyTurlaDarkWatchmanCyclops BlinkMythicSmall SieveKEYPLUGWoody RATBADHATCHSardonicCOATHANGERLITTLELAMB.WOOLTEAMispaduPITSTOPLunarWebFRPCovenantSnappyTCPMangoOilBoosterBOLDMOVENICECURLGomirJ-magicSagerunexLumma StealerREPTILECASTLETAPBRICKSTORMDCRATPureCrypterHiddenFaceLAMEHUG

Corpus indicators tagged with this technique

123 indicators in the corpus carry T1573.002.

IndicatorTypeFamilySevSrc
0ca2edf9982f58e63cc49ba69fb9a88762d1f220ed9482810b512d4add0f8f0bhashransomware801
0f7463aecc3920f9e2b32ab9d77861a9e69a3e8aa28d06b4602195623312331dhashransomware801
123e80a34508c4dede7cc70e76931fcchash803
069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44cehashsupply_chain801
0dfe9d56066fd9005f210a903645ed90hashransomware801
ebcf977806f68af3147e0b78b55f6aedhash802
625b6535321d58bb5c613e85332bf731hash803
873f1277a42de5c82f869459e7fb7c94554a642bhash803
681075027553546c119ec447eb8df84633dcffcehash803
00e195d94d3b1f7092eb9ed132f89d1bhash803
04e7a98fb3b7738cca42557c3e2d9906d04fa2f6hash803
1852120a84a328edd1995e633dfd2009867898a8e3f0b385e2490cf21c77a994hash803
2654c08491a0f7c4a3dfc6282de5638bhash803
46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93hashransomware801
4c357a29b202b77e7db190d359ead2dfd3f8869c6808b96bfa8bee82525bb2a2hashransomware801
6870e3bbf2447c96d21682caf943cf31c2e8c21c8cfb91a5092eab1c9e5f19aehashransomware801
75635009a00cb26d2f532ad974ede59785a18e4b30132a1f585108589394ba5ahashransomware801
a5a5b6257304eefe5212edfd8c0ad27f77357c5046a7acb8eb7ba72ed4bad9e0hashransomware801
ac66c2d47cdefb221822b9074c9810434e8da702a0694139aa9177557e6b292bhashransomware801
ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7echashransomware801
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
08060143ea9b55b480746b415af22e3ahashransomware801
9c44bc9373377831c45dd0ac2661a28ehash803
b148626849c11dd5b3230632a38a6302hashransomware802
cc19e502e4201cc974c753b96429027925224f53hash802
15d1002d9935fbfc9dfc65eb70fe4ecc0943c784hashransomware801
e5c4e634b2f443f783cae1b5e8247a1069df0c9fhashransomware802
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984hashransomware802
4b7dbb7d5bc8938747b39faf602d85c3587ae261hashransomware801

Showing the top 30 by severity of 123.