LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1573: Encrypted Channel

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

EnterpriseT1573TechniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Encrypted Channel (T1573) matters because it lets command-and-control traffic blend into environments where encryption is normal. The business issue is not simply “encrypted traffic exists”; it is whether the organization can distinguish legitimate encrypted communications from malware-controlled sessions when payload content may be hidden. This affects SOC visibility, incident response speed, and—where operational technology or network devices are in scope—resilience decisions during a suspected compromise.

Executive priority

Leaders should treat this as a visibility and control-prioritization question. Ask whether critical platforms listed by ATT&CK—Windows, Linux, macOS, ESXi, and network devices—generate enough network and endpoint evidence to investigate encrypted C2 without relying only on content inspection. Budget and risk decisions should balance SSL/TLS inspection and network intrusion prevention against privacy, operational, and inspection-risk considerations noted by ATT&CK’s references and mitigation relationships. The relationship to the Triton Safety Instrumented System Attack and KV Botnet Activity makes this especially relevant for organizations with cyber-physical operations, critical infrastructure exposure, or unmanaged/end-of-life network equipment.

Technical view

For SOC, detection engineering, and IR teams, validate coverage around command-and-control over encrypted channels rather than assuming protocol encryption is benign. ATT&CK does not provide native detection text for T1573, so teams should anchor detection work to the related detection strategy DET0273, the mitigation relationships for SSL/TLS Inspection (M1020) and Network Intrusion Prevention (M1031), and the sub-techniques for symmetric and asymmetric cryptography. Practical validation should include whether analysts can correlate encrypted network sessions with process, host, user, destination, certificate, and device context across Windows, Linux, macOS, ESXi, and network devices. Malware relationships such as gh0st RAT, NETWIRE, Emotet, Cryptoistic, Chaes, RCSession, Lizar, PowerLess, MacMa, and PowGoop show that this behavior is not limited to one operating system or tool family.

Likely telemetry

  • Network flow records and connection metadata for encrypted outbound and lateral communications
  • TLS/SSL inspection logs where inspection is authorized and technically feasible
  • Network intrusion detection/prevention alerts and signature matches at boundaries
  • DNS, proxy, and secure web gateway logs associated with encrypted sessions
  • Endpoint process-to-network connection telemetry on Windows, Linux, macOS, and ESXi where available

Detection direction

  • Do not depend only on decrypting payloads; validate metadata-based detections for unusual encrypted session patterns, rare destinations, unexpected processes initiating encrypted connections, and abnormal timing or volume.
  • Where SSL/TLS inspection is deployed, confirm scope, exclusions, privacy constraints, certificate handling, and operational risks; inspection gaps can become blind spots.
  • Tune detections by platform and asset role. Encrypted traffic from servers, ESXi hosts, network devices, or administrative systems should be baselined differently from normal user browsing.
  • Use relationship context to test coverage against both symmetric and asymmetric encrypted C2 patterns, without assuming a single protocol or algorithm.
  • Correlate network alerts with endpoint and identity context to reduce false positives from legitimate encrypted business applications.

Mitigation priorities

  • Prioritize network intrusion prevention at network boundaries where signatures and policy controls can block known malicious traffic patterns.
  • Evaluate SSL/TLS inspection for high-risk network segments, egress paths, and investigative workflows, while accounting for the inspection risks and limitations identified in ATT&CK references.
  • Strengthen egress visibility and policy enforcement for critical assets, network devices, ESXi infrastructure, and systems supporting operational resilience.
  • Maintain endpoint-to-network correlation so encrypted C2 investigations are not blocked when payload inspection is unavailable or inappropriate.
  • For environments with critical infrastructure or cyber-physical exposure, include encrypted C2 scenarios in incident response and business continuity exercises.
Additional notes and limits

T1573 consolidates earlier revoked techniques for custom cryptographic protocol, standard cryptographic protocol, and multilayer encryption, so historical analytics may need ATT&CK mapping updates. The supplied relationships show usage by multiple groups, campaigns, and software families, but they should be used for contextual prioritization, not as proof of current activity in any given environment.

ATT&CK provides no official detection text for this technique in the supplied object. Specific detection logic, thresholds, and inspection feasibility require local network architecture, privacy policy, asset criticality, and telemetry validation. The supplied relationship descriptions are partial in places, and this take does not infer exposure or active exploitation beyond the listed ATT&CK relationships.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Encrypted Channel

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

5 rows
DomainIDNameRelationship / procedure
EnterpriseT1573.002Asymmetric CryptographySub-techniqueAsymmetric Cryptography subtechnique of this object.
EnterpriseT1024Custom Cryptographic ProtocolCustom Cryptographic Protocol revoked by this object.
EnterpriseT1032Standard Cryptographic ProtocolStandard Cryptographic Protocol revoked by this object.
EnterpriseT1573.001Symmetric CryptographySub-techniqueSymmetric Cryptography subtechnique of this object.
EnterpriseT1079Multilayer EncryptionMultilayer Encryption revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0081: Tropic Trooper

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.[1][2][3]

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]

GroupEnterprise

G1002: BITTER

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.[1][2]

GroupEnterprise

G0016: APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).[1][2] They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.[3][4][5][6]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes.[7][8] Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.[9][10][11][12][13][14]

MalwareEnterprise

S0631: Chaes

Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.[1]

Windows
MalwareEnterprise

S0681: Lizar

Lizar is a modular remote access tool written using the .NET Framework that shares structural similarities to Carbanak. It has likely been used by FIN7 since at least February 2021.[1][2][3]

Windows
MalwareEnterprise

S0198: NETWIRE

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.[1][2][3]

WindowsLinuxmacOS
MalwareEnterprise

S1016: MacMa

MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021.[1] MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.[2]

macOS
MalwareEnterprise

S0367: Emotet

Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.[1]

Windows
CampaignEnterprise

C0035: KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]

CampaignEnterprise

C0030: Triton Safety Instrumented System Attack

Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical organization.[1] The malware and techniques used within this campaign targeted specific Triconex Safety Controllers within the environment.[2] The incident was eventually discovered due to a safety trip that occurred as a result of an issue in the malware.[3]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
118c1231f501f60b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle118c1231f501…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  2. [2]
    SentinelOne Lazarus macOS July 2020

    Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.

    Open source URL
  3. [3]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  4. [4]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  5. [5]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  6. [6]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  7. [7]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  8. [8]
    Cybereason PowerLess February 2022

    Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.

    Open source URL
  9. [9]
    Forcepoint BITTER Pakistan Oct 2016

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

    Open source URL
  10. [10]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  11. [11]
    Secureworks IRON HEMLOCK Profile

    Secureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.

  12. [12]
    Threatpost Lizar May 2021

    Seals, T. (2021, May 14). FIN7 Backdoor Masquerades as Ethical Hacking Tool. Retrieved February 2, 2022.

    Open source URL
  13. [13]
    BiZone Lizar May 2021

    BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.

    Open source URL
  14. [14]
    Cocomazzi FIN7 Reboot

    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.

    Open source URL
  15. [15]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
  16. [16]
    FireEye TEMP.Veles 2018

    FireEye Intelligence . (2018, October 23). TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers. Retrieved April 16, 2019.

    Open source URL
  17. [17]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  18. [18]
    ESET DazzleSpy Jan 2022

    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

    Open source URL
  19. [19]
    Fortinet Emotet May 2017

    Xiaopeng Zhang. (2017, May 3). Deep Analysis of New Emotet Variant – Part 1. Retrieved April 1, 2019.

    Open source URL
  20. [20]
    SANS Decrypting SSL

    Butler, M. (2013, November). Finding Hidden Threats by Decrypting SSL. Retrieved April 5, 2016.

  21. [21]
    SANS Decrypting SSL

    Butler, M. (2013, November). Finding Hidden Threats by Decrypting SSL. Retrieved April 5, 2016.

  22. [22]
    SANS Decrypting SSL

    Butler, M. (2013, November). Finding Hidden Threats by Decrypting SSL. Retrieved April 5, 2016.

  23. [23]
    SEI SSL Inspection Risks

    Dormann, W. (2015, March 13). The Risks of SSL Inspection. Retrieved April 5, 2016.

    Open source URL
  24. [24]
    SEI SSL Inspection Risks

    Dormann, W. (2015, March 13). The Risks of SSL Inspection. Retrieved April 5, 2016.

    Open source URL
  25. [25]
    SEI SSL Inspection Risks

    Dormann, W. (2015, March 13). The Risks of SSL Inspection. Retrieved April 5, 2016.

    Open source URL
  26. [26]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  27. [27]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  28. [28]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  29. [29]
    mitre-attackT1573
    Open source URL
  30. [30]
    mitre-attackT1573
    Open source URL
  31. [31]
    mitre-attackT1573
    Open source URL
  32. [32]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  33. [33]
    SentinelOne Lazarus macOS July 2020

    Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.

    Open source URL
  34. [34]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  35. [35]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  36. [36]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  37. [37]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  38. [38]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  39. [39]
    Cybereason PowerLess February 2022

    Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.

    Open source URL
  40. [40]
    Forcepoint BITTER Pakistan Oct 2016

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

    Open source URL
  41. [41]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  42. [42]
    Secureworks IRON HEMLOCK Profile

    Secureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.

  43. [43]
    BiZone Lizar May 2021

    BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.

    Open source URL
  44. [44]
    Cocomazzi FIN7 Reboot

    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.

    Open source URL
  45. [45]
    Threatpost Lizar May 2021

    Seals, T. (2021, May 14). FIN7 Backdoor Masquerades as Ethical Hacking Tool. Retrieved February 2, 2022.

    Open source URL
  46. [46]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.