MITRE ATT&CK sub-technique
T1560.001 — Archive via Utility
Last fetched
T1560.001 (Archive via Utility) is a MITRE ATT&CK sub-technique tracked in WhisperGraph, serving the Collection tactic.
Description
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as <code>tar</code> on Linux and macOS or <code>zip</code> on Windows systems. On Windows, <code>diantz</code> or <code> makecab</code> may be used to package collected files into a cabinet (.cab) file. <code>diantz</code> may also be used to download and compress files from remote locations (i.e. [Remote Data Staging](https://attack.mitre.org/techniques/T1074/002)).(Citation: diantz.exe_lolbas) <code>xcopy</code> on Windows can copy files and directories with a variety of options. Additionally, adversaries may use [certutil](https://attack.mitre.org/software/S0160) to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.(Citation: 7zip Homepage)(Citation: WinRAR Homepage)(Citation: WinZip Homepage)
Tactics
Related techniques
Parent technique: T1560 · Archive Collected Data
Threat actors observed using this technique
- Agrius
- INC Ransom
- CopyKittens
- Volt Typhoon
- Akira
- Mustang Panda
- ToddyCat
- Play
- Sowbug
- Earth Lusca
- APT5
- APT3
- UNC3886
- APT1
- BRONZE BUTLER
- MirrorFace
- Ke3chang
- Fox Kitten
- menuPass
- FIN13
- Gallmaker
- Wizard Spider
- APT41
- Turla
- MuddyWater
- APT39
- APT33
- Lotus Blossom
- Magic Hound
- Aquatic Panda
- APT28
- GALLIUM
- VOID MANTICORE
- Kimsuky
- FIN8
- Sea Turtle
- Chimera
- HAFNIUM
- RedCurl
- WIZARD SPIDER
- MUSTANG PANDA
- Void Manticore
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1560.001 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.