Official Description

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Tactics
Command And Control
Platforms
ESXi, Linux, macOS, Network Devices, Windows
MITRE Version
1.2
Last Modified
Oct 24, 2025

View on MITRE ATT&CK ↗

Sub-techniques (2)