T1573.001: T1573.001
Essential information
- MITRE technique ID
T1573.001- Confidence
- 100/100
- Revoked
- No
- Published
- 16/03/2020 16:45
- Modified
- 27/03/2026 01:08
- Author / Source
- The MITRE Corporation
Aliases
Symmetric Cryptography
Platforms
windows macos linux Network Devices ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (57)
-
GlassWorm relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Harvester relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Higaisa relatedThe MITRE Corporation Confidence 100
[Higaisa](https://attack.mitre.org/groups/G0126) is a threat group suspected to have South Korean origins. [Higaisa](https://attack.mitre.org/groups/G0126) has targeted government, public, and trade organizations in North Korea; however, they have also carried out…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Hive0145 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active…
First seen 01/01/1970 · Last seen 16/11/5138 · -
KONNI relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Konni Group relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lazarus relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LegionLoader relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (79)
-
Hikit usesFamily The MITRE Corporation Confidence 100
[Hikit](https://attack.mitre.org/software/S0009) is malware that has been used by [Axiom](https://attack.mitre.org/groups/G0001) for late-stage persistence and exfiltration after the initial compromise.(Citation: Novetta-Axiom)(Citation: FireEye Hikit Rootkit)
First seen 01/01/1970 · Last seen 16/11/5138 · -
QUIC RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Remcos usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NDiskMonitor usesFamily The MITRE Corporation Confidence 100
[NDiskMonitor](https://attack.mitre.org/software/S0272) is a custom backdoor written in .NET that appears to be unique to [Patchwork](https://attack.mitre.org/groups/G0040). (Citation: TrendMicro Patchwork Dec 2017)
First seen 01/01/1970 · Last seen 16/11/5138 · -
CoolClient usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
GammaPhish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mafalda usesFamily The MITRE Corporation Confidence 100
[Mafalda](https://attack.mitre.org/software/S1060) is a flexible interactive implant that has been used by [Metador](https://attack.mitre.org/groups/G1013). Security researchers assess the [Mafalda](https://attack.mitre.org/software/S1060) name may be inspired by an Argentinian cartoon character that has…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Gazer usesFamily The MITRE Corporation Confidence 100
[Gazer](https://attack.mitre.org/software/S0168) is a backdoor used by [Turla](https://attack.mitre.org/groups/G0010) since at least 2016. (Citation: ESET Gazer Aug 2017)
First seen 01/01/1970 · Last seen 16/11/5138 · -
down_new usesFamily The MITRE Corporation Confidence 100
[down_new](https://attack.mitre.org/software/S0472) is a downloader that has been used by [BRONZE BUTLER](https://attack.mitre.org/groups/G0060) since at least 2019.(Citation: Trend Micro Tick November 2019)
First seen 01/01/1970 · Last seen 16/11/5138 · -
RTM usesFamily The MITRE Corporation Confidence 100
[RTM](https://attack.mitre.org/software/S0148) is custom malware written in Delphi. It is used by the group of the same name ([RTM](https://attack.mitre.org/groups/G0048)). Newer versions of the malware have been reported publicly as…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Stellar loader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Interlock usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
AlienVault Confidence 100 20 MITREs 3 Malwares 28 IOCs 8 Observables
-
AlienVault Confidence 100 1 CVE 18 MITREs 1 Malware 140 IOCs 127 Observables
-
AlienVault Confidence 100 19 MITREs 3 Malwares 6 IOCs 1 APT
-
AlienVault Confidence 100 20 MITREs 2 Malwares 11 IOCs 7 Observables 1 APT
-
AlienVault Confidence 100 25 MITREs 6 Malwares 39 IOCs 24 Observables
-
AlienVault Confidence 100 13 CVEs 22 MITREs 6 Malwares 5 IOCs 4 Observables
-
AlienVault Confidence 100 20 MITREs 1 Malware 3 IOCs 1 APT
-
AlienVault Confidence 100 19 MITREs 3 Malwares 4 IOCs 1 APT
-
AlienVault Confidence 100 20 MITREs 9 IOCs 3 Observables
-
AlienVault Confidence 100 8 MITREs 5 Malwares 200 IOCs 200 Observables
-
AlienVault Confidence 100 17 MITREs 1 Malware 12 IOCs 12 Observables 1 APT
-
AlienVault Confidence 100 20 MITREs 10 IOCs 10 Observables
Vulnerabilities (CVE) (52)
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker …
- Attack vector
- Network
- Published
- 13/02/2026
- Modified
- 20/02/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions …
- Attack vector
- NETWORK
- Published
- 27/10/2022
- Modified
- 21/12/2025
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve …
- Attack vector
- Network
- Published
- 02/06/2025
- Modified
- 21/12/2025
Tool (2)
-
QuasarRAT usesThe MITRE Corporation Confidence 100
[QuasarRAT](https://attack.mitre.org/software/S0262) is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. [QuasarRAT](https://attack.mitre.org/software/S0262) is developed in the C# language.(Citation: GitHub QuasarRAT)(Citation: Volexity…
-
Sliver usesThe MITRE Corporation Confidence 100
[Sliver](https://attack.mitre.org/software/S0633) is an open source, cross-platform, red team command and control (C2) framework written in Golang. [Sliver](https://attack.mitre.org/software/S0633) includes its own package manager, "armory," for staging and downloading additional…