MITRE ATT&CK Technique
T1001.002Steganography
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Official Description
Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.
- Tactics
- Command And Control
- Platforms
- Linux, macOS, Windows, ESXi
- Parent Technique
- T1001 · Data Obfuscation
- MITRE Version
- 1.1
- Last Modified
- Oct 24, 2025
Reported Context (1)
- C2 exchanges appeared to contain JPEG files, but the images held encoded data that the malware extracted and decoded. TerminalFix Lures and Lorem Ipsum Loader Deploy a Covert Tunneling Implant
Malware (2)
Threat Actors (6)
MITRE ATT&CK (10)
Vendors (1)
Products (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.