FORENSIA

ATT&CK · T1001.002 · sub-technique

Steganography

Tactics: command-and-control

About

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.

Platforms: Linux, macOS, Windows, ESXiParent: T1001 Data ObfuscationMITRE ATT&CK ↗

Used by actors

1 known groups

Software

11 malware/tools implement this

HAMMERTOSSDuquDaserfZeroTLightNeuronRDATSUNBURSTSliverZoxLunarWebLunarMail

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1001.002.

No corpus indicators are tagged with this technique yet.