Description
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network.(Citation: DOJ GRU Indictment Jul 2018) Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.
Threat-Mapped Scoring
Threat Score:
0.0
Industry:
Threat Priority:
Unclassified
ATT&CK Kill Chain Metadata
- Tactics: collection
- Platforms: Linux, macOS, Windows
-
Detection Guidance:
Archival software and archived files can be detected in many ways. Common utilities that may be present on the system or brought in by an adversary may be detectable through process monitoring and monitoring for command-line arguments for known archival utilities. This may yield a significant number of benign events, depending on how systems in the environment are typically used. A process that loads the Windows DLL crypt32.dll may be used to perform encryption, decryption, or verification of file signatures. Consider detecting writing of files with extensions and/or headers associated with compressed or encrypted file types. Detection efforts may focus on follow-on exfiltration activity, where compressed or encrypted files can be detected in transit with a network intrusion detection or data loss prevention system analyzing file headers.(Citation: Wikipedia File Header Signatures)
Malware
- ADVSTORESHELL
- Agent Tesla
- AppleSeed
- Aria-body
- BLUELIGHT
- Backdoor.Oldrea
- Bumblebee
- Cadelspy
- Chrommme
- Daserf
- Dtrack
- Epic
- Exaramel for Windows
- FELIXROOT
- Gold Dragon
- JumbledPath
- KONNI
- Kessel
- LightNeuron
- Lizar
- LoFiSe
- Lurid
- Machete
- NETWIRE
- Pillowmint
- PowerLess
- Prikormka
- Proton
- Raccoon Stealer
- Remexi
- RunningRAT
- Spica
- TAINTEDSCRIBE
- Troll Stealer
- VERMIN
- WellMail
- XCSSET
- Zebrocy