ATT&CK · T1001
Data Obfuscation
Tactics: command-and-control
About
Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.
Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
1 known groups
Software
13 malware/tools implement this
FlawedAmmyyOkrumRDATSLOTHFULMEDIASideTwistTrailBlazerFunnyDreamNinjaDarkGateFRAMESTINGStrelaStealerSystemBCevilginx2
Corpus indicators tagged with this technique
10 indicators in the corpus carry T1001.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| 4912b1134e69ade7266e8508eec33ccb2d80ad693f1dbc4f1f4344c6dfcf2ff1 | hash | — | 80 | 2 |
| d7545b6dacebdae27effb3c778c5e349027ec789c76ae4f777bd9ba56a70cdaa | hash | — | 80 | 2 |
| 38dfeb772afbd01c04eddda120d283acfb1147a6dc3d54ac62fe23ad06e39d8f | hash | — | 80 | 2 |
| ecdc8fade561a75d68235859ad8b1fe131db2c458b4894268e38e90ecab1c47f | hash | — | 80 | 2 |
| http://24.199.90.58:80/payload.php | url | — | 75 | 1 |
| https://convitemundial2026.com/consultar_nf-e.bat | url | — | 75 | 1 |
| http://24.199.90.58/payload.php | url | — | 75 | 2 |
| c.windowsk-cdn.com | domain | — | 65 | 2 |
| windowsk-cdn.com | domain | — | 65 | 2 |
| convitemundial2026.com | domain | — | 65 | 2 |