T1521.001 Symmetric Cryptography
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, Blowfish, and RC4.
| Item | Value |
|---|---|
| ID | T1521.001 |
| Sub-techniques | T1521.001, T1521.002, T1521.003 |
| Tactics | TA0037 |
| Platforms | Android, iOS |
| Version | 1.0 |
| Created | 05 April 2022 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| C0033 | C0033 | During C0033, PROMETHIUM used StrongPity to encrypt C2 communication using AES.6 |
| S0478 | EventBot | EventBot has encrypted base64-encoded payload data using RC4 and Curve25519.1 |
| C0054 | Operation Triangulation | During Operation Triangulation, the threat actors used 3DES and AES to encrypt C2 communication and data.27 |
| S0411 | Rotexy | Rotexy encrypts JSON HTTP payloads with AES.4 |
| S1055 | SharkBot | SharkBot can use RC4 to encrypt C2 payloads.3 |
| S1216 | TriangleDB | TriangleDB has encrypted data using 3DES.2 |
| G0112 | Windshift | Windshift has encrypted C2 communications using AES in CBC mode during Operation BULL and Operation ROCK.5 |
References
-
D. Frank, L. Rochberger, Y. Rimmer, A. Dahan. (2020, April 30). EventBot: A New Mobile Banking Trojan is Born. Retrieved June 26, 2020. ↩
-
Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024. ↩↩
-
RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023. ↩
-
T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019. ↩
-
The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021. ↩
-
Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023. ↩
-
Kucherin, G., et al. (2023, October 23). The outstanding stealth of Operation Triangulation. Retrieved April 18, 2024. ↩