#T1560.002 Archive via Library
Technique
- Tactics: Collection
- Description:
An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including [Python](https://attack.mitre.org/techniques/T1059/006) rarfile (Citation: PyPI RAR), libzip (Citation: libzip), and zlib (Citation: Zlib Github). Most libraries include functionality to encrypt and/or compress data.
Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. The libraries can be linked against when compiling, while the utilities require spawning a subshell, or a similar execution mechanism.
- First Seen: ScarCruft surveilling North Korean defectors and human rights activists • 2021-11-29
-
8
Tagged Reports
-
5
Unique Authors
-
1,354
Active Days
Tagged Reports
2025-08-13
Cyfirma
2025-02-20
ESET
2023-09-27
Ptsecurity
2022-11-30
ESET
2021-12-02
SOCRadar