ATT&CK · T1560.002 · sub-technique
Archive via Library
Tactics: collection
About
An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including Python rarfile, libzip, and zlib. Most libraries include functionality to encrypt and/or compress data. Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. The libraries can be linked against when compiling, while the utilities require spawning a subshell, or a similar execution mechanism.
Used by actors
2 known groups
Software
13 malware/tools implement this
Corpus indicators tagged with this technique
0 indicators in the corpus carry T1560.002.
No corpus indicators are tagged with this technique yet.