Archive Collected Data: Archive via Utility

An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities. Many utilities exist that can archive data, including 7-Zip[1], WinRAR[2], and WinZip[3]. Most utilities include functionality to encrypt and/or compress data.

Some 3rd party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.

ID: T1560.001
Sub-technique of:  T1560
Tactic: Collection
Platforms: Linux, Windows, macOS
Data Sources: Command: Command Execution, File: File Creation, Process: Process Creation
Version: 1.0
Created: 20 February 2020
Last Modified: 25 March 2020

Procedure Examples

ID Name Description
G0006 APT1

APT1 has used RAR to compress files before moving them outside of the victim network.[4]

G0016 APT29

APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfiltration.[5][6]

G0022 APT3

APT3 has used tools to compress data before exfilling it.[7]

G0064 APT33

APT33 has used WinRAR to compress data prior to exfil.[8]

G0087 APT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data. [9]

G0096 APT41

APT41 created a RAR archive of targeted files for exfiltration.[10]

G0060 BRONZE BUTLER

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.[11][12]

S0274 Calisto

Calisto uses the zip -r command to compress the data collected on the local system.[13][14]

G0114 Chimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.[15][16]

G0052 CopyKittens

CopyKittens uses ZPP, a .NET console program, to compress files with ZIP.[17]

S0212 CORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.[18]

S0538 Crutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.[19]

S0187 Daserf

Daserf hides collected data in password-protected .rar archives.[20]

S0062 DustySky

DustySky can compress files via RAR while staging data to be exfiltrated.[21]

G0061 FIN8

FIN8 has used RAR to compress collected data before Exfiltration.[22]

G0117 Fox Kitten

Fox Kitten has used 7-Zip to archive data.[23]

G0093 GALLIUM

GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration.[24][25]

G0084 Gallmaker

Gallmaker has used WinZip, likely to archive data prior to exfiltration.[26]

G0125 HAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.[27][28]

S0278 iKitten

iKitten will zip up the /Library/Keychains directory before exfiltrating it.[29]

S0260 InvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.[30]

G0004 Ke3chang

Ke3chang is known to use RAR with passwords to encrypt data prior to exfiltration.[31]

G0059 Magic Hound

Magic Hound has used RAR to stage and compress local folders.[32]

G0045 menuPass

menuPass has compressed files before exfiltration using TAR and RAR.[33][34][35]

S0339 Micropsia

Micropsia creates a RAR archive based on collected files on the victim's machine.[36]

G0069 MuddyWater

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.[37]

G0129 Mustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration.[38][39]

S0439 Okrum

Okrum was seen using a RAR archiver tool to compress/decompress data.[40]

S0264 OopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.[41]

G0116 Operation Wocao

Operation Wocao has archived collected files with WinRAR, prior to exfiltration.[42]

S0428 PoetRAT

PoetRAT has the ability to compress files with zip.[43]

S0378 PoshC2

PoshC2 contains a module for compressing data using ZIP.[44]

S0441 PowerShower

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.[45]

S0196 PUNCHBUGGY

PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil.[46]

S0192 Pupy

Pupy can compress data with Zip before sending it over C2.[47]

S0458 Ramsay

Ramsay can compress and archive collected files using WinRAR.[48][49]

G0054 Sowbug

Sowbug extracted documents and bundled them into a RAR archive.[50]

G0010 Turla

Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration.[51]

S0466 WindTail

WindTail has the ability to use the macOS built-in zip utility to archive files.[52]

Mitigations

ID Mitigation Description
M1047 Audit

System scans can be performed to identify unauthorized archival utilities.

Detection

Common utilities that may be present on the system or brought in by an adversary may be detectable through process monitoring and monitoring for command-line arguments for known archival utilities. This may yield a significant number of benign events, depending on how systems in the environment are typically used.

Consider detecting writing of files with extensions and/or headers associated with compressed or encrypted file types. Detection efforts may focus on follow-on exfiltration activity, where compressed or encrypted files can be detected in transit with a network intrusion detection or data loss prevention system analyzing file headers.[53]

References

  1. I. Pavlov. (2019). 7-Zip. Retrieved February 20, 2020.
  2. A. Roshal. (2020). RARLAB. Retrieved February 20, 2020.
  3. Corel Corporation. (2020). WinZip. Retrieved February 20, 2020.
  4. Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  5. Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
  6. MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
  7. valsmith. (2012, September 21). More on APTSim. Retrieved September 28, 2017.
  8. Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
  9. Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.
  10. Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
  11. Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
  12. Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.
  13. Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.
  14. Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.
  15. Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020.
  16. Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved January 19, 2021.
  17. ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.
  18. FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved March 1, 2018.
  19. Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.
  20. DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.
  21. GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.
  22. Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.
  23. CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.
  24. Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
  25. MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.
  26. Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.
  27. MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.
  1. Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.
  2. Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.
  3. Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.
  4. Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
  5. Mandiant. (2018). Mandiant M-Trends 2018. Retrieved July 9, 2018.
  6. PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.
  7. PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
  8. Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.
  9. Tsarfaty, Y. (2018, July 25). Micropsia Malware. Retrieved November 13, 2018.
  10. Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.
  11. Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.
  12. Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.
  13. Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.
  14. Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.
  15. Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.
  16. Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.
  17. Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.
  18. GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.
  19. Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.
  20. Nicolas Verdier. (n.d.). Retrieved January 29, 2018.
  21. Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.
  22. Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.
  23. Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.
  24. Symantec DeepSight Adversary Intelligence Team. (2019, June 20). Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments. Retrieved July 8, 2019.
  25. Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.
  26. Wikipedia. (2016, March 31). List of file signatures. Retrieved April 22, 2016.