T1573.001 - Symmetric Cryptography
Sub-technique
Tactics:
Command and Control
Command and Control
Platforms:
ESXi Linux macOS Network Devices +1
ESXi Linux macOS Network Devices +1
Detection:
Not specified
Not specified
Description:
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Used by Actors (14)
DarkHotel
Nation-state
Nation-state
APT33
Nation-state
Nation-state
APT28
Nation-state
Nation-state
Lazarus Group
Nation-state
Nation-state
Stealth Falcon
Nation-state
Nation-state
MuddyWater
Nation-state
Nation-state
MUSTANG PANDA
Nation-state
Nation-state
Higaisa
Nation-state
Nation-state
Volt Typhoon
Unknown
Unknown
Inception
Unknown
Unknown
BRONZE BUTLER
Unknown
Unknown
RedCurl
Unknown
Unknown
Contagious Interview
Unknown
Unknown
ZIRCONIUM
Unknown
Unknown
Malware (20)
Metadata
| MITRE ID: | T1573.001 |
| STIX ID: | attack-pattern--24bfaeba-cb0d-... |
| Platforms: | ESXi, Linux, macOS, Network Devices, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 07/03/2026 16:00 |