#T1032 Standard Cryptographic Protocol

Technique

  • Tactics: Command And Control
  • Description:

    Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if necessary secret keys are encoded and/or generated within malware samples/configuration files.

  • First Seen: Lazarus group leverages Covid themed HWP Document • 2020-05-09
MITRE ATT&CK

Tagged Reports

« Back