MITRE ATT&CK Technique
T1573.001Symmetric Cryptography
- First Reported
- Sep 13, 2026
- Latest Reported
- Sep 30, 2026
Official Description
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Network Devices, Windows
- Parent Technique
- T1573 · Encrypted Channel
- MITRE Version
- 1.2
- Last Modified
- May 12, 2026
Reported Context (3)
- 2CLoader XOR-encrypts JSON messages before sending them to its C2 server. 2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus
- Kothamine encrypted and decrypted messages exchanged with its command-and-control endpoint using AES-GCM. Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control
- JITTERLY encrypts its custom TCP command-and-control messages with per-session AES-128-GCM keys. Red Heron Exploits Gitea CVE-2026-60004 in Multinational Campaign, Deploys Linux Rootkit
CVE (1)
Malware (6)
Threat Actors (1)
MITRE ATT&CK (31)
Vendors (3)
Products (11)
Tools (6)
Industries (11)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.