T1560.001 Archive via Utility — ATT&CK Technique
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. On Windows, diantz or makecab may be used to package collected files into a cabinet (.cab) file. diantz may also be used to download and compress files from remote locations (i.e. Remote Data Staging). xcopy on Windows can copy files and directories with a variety of options. Additionally, adversaries may use certutil to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.
Detection coverage (23)
- LiteLLM / TeamPCP Supply Chain Attack Indicators high
- Password Protected Compressed File Extraction Via 7Zip low
- Potentially Suspicious Compression Tool Parameters medium
- Cisco Stage Data low
- Disk Image Mounting Via Hdiutil - MacOS medium
- Data Compressed low
- Rar Usage with Password and Compression Level high
- Files Added To An Archive Using Rar.EXE low
- Compress Data and Lock With Password for Exfiltration With 7-ZIP medium
- 7Zip Compressing Dump Files medium
- Suspicious Manipulation Of Default Accounts Via Net.EXE high
- Compressed File Creation Via Tar.EXE low
- Compressed File Extraction Via Tar.EXE low
- Winrar Compressing Dump Files medium
- WinRAR Execution in Non-Standard Folder medium
- Compress Data and Lock With Password for Exfiltration With WINZIP medium
- 7zip CommandLine To SMB Share Path
- Anomalous usage of 7zip
- Detect Renamed 7-Zip
- Detect Renamed WinRAR
- IcedID Exfiltrated Archived File Creation
- Windows Archive Collected Data via Rar
- APT31 Judgement Panda Activity critical
Malware using this technique
- WindTail
- InvisibleFerret
- TONESHELL
- iKitten
- Turian
- PUBLOAD
- InvisiMole
- Okrum
- PowerShower
- Daserf
- PUNCHBUGGY
- BeaverTail
- DustySky
- SampleCheck5000
- Sagerunex
- GlassWorm
- CORALDECK
- Micropsia
- OopsIE
- Crutch
- ccf32
- Calisto
- Ramsay
- Pupy
- LAMEHUG
- PoetRAT
- IceApple
- LunarWeb
- Octopus
- TeamPCP Cloud Stealer
- Mini Shai-Hulud
- certutil
- PoshC2
- Rclone
- AppleSeed
- Remcos
Threat actors using this technique
- Void Manticore
- Play Ransomware
- GALLIUM
- APT3
- Kimsuky
- Volt Typhoon
- APT41
- APT10
- HAFNIUM
- MuddyWater
- Gallmaker
- Mustang Panda
- APT39
- UNC3886
- Akira
- APT35
- Sea Turtle
- Aquatic Panda
- APT15
- APT1
- Turla
- APT33
- RedCurl
- Lotus Blossom
- Chimera
- MirrorFace
- BRONZE BUTLER
- FIN8
- Agrius
- APT28
- APT5
- Fox Kitten
- INC Ransom
- Earth Lusca
- Sowbug
- CopyKittens
- Conti
- ToddyCat
- FIN13