FORENSIA

ATT&CK · T1560.002 · sub-technique

Archive via Library

Tactics: collection

About

An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including Python rarfile, libzip, and zlib. Most libraries include functionality to encrypt and/or compress data. Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. The libraries can be linked against when compiling, while the utilities require spawning a subshell, or a similar execution mechanism.

Platforms: Linux, macOS, WindowsParent: T1560 Archive Collected DataMITRE ATT&CK ↗

Used by actors

2 known groups

Software

13 malware/tools implement this

SeaDukeZLibEpicBBSRATInvisiMoleCardinal RATOSX_OCEANLOTUS.DDenisTajMahalBADFLICKFoggyWebFunnyDreamLunarWeb

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1560.002.

No corpus indicators are tagged with this technique yet.