T1573 Encrypted Channel — ATT&CK Technique

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Detection coverage (8)

Malware using this technique

Threat actors using this technique

Read the full analysis on IntelFusions