T1573.001 Symmetric Cryptography — ATT&CK Technique
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Malware using this technique
- TrickBot
- BLINDINGCAN
- Ninja
- Pikabot
- Bumblebee
- Torisma
- Stuxnet
- Downdelph
- Bandook
- PipeMon
- RotaJakiro
- Sardonic
- Emissary
- KEYMARBLE
- TAMECAT
- CASTLETAP
- RedLeaves
- Havoc
- xCaon
- Lurid
- TONESHELL
- NETWIRE
- BOOKWORM
- HyperStack
- HAMMERTOSS
- CosmicDuke
- GreyEnergy
- Emotet
- SNUGRIDE
- THINCRUST
- Machete
- Prikormka
- PUBLOAD
- SystemBC
- WellMess
- Mafalda
- SombRAT
- FlawedAmmyy
- Rifdoor
- InvisiMole
- Volgmer
- ZeroT
- RDAT
- Okrum
- Bonadan
- RustyWater
- UBoatRAT
- HTTPTroy
- NETEAGLE
- FatDuke