T1573: Encrypted Channel

command-and-control

Summary

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Source Attribution

Source: MITRE ATT&CK · Confidence: high

Platforms

  • ESXi
  • Linux
  • macOS
  • Network Devices
  • Windows

Tactic

command-and-control

References