T1560.001Archive via Utility
T1560.001 — Archive via Utility is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 16 detection use cases covering it and 10 threat-intel articles citing it.
Collection
16Use cases
10Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1560 · Archive Collected Data
Use cases covering this technique (16)
7zip CommandLine To SMB Share Path Anomalous usage of 7zip Detect Renamed 7-Zip Detect Renamed WinRAR IcedID Exfiltrated Archived File Creation Windows Archive Collected Data via Rar [LLM] GoSerpent 7-Zip archiving with hardcoded campaign password @vx0a9n5W2M0c3D6.# [LLM] Password-protected RAR staging of data for exfiltration (-hp) [LLM] macOS.Gaslight keychain theft + collected_data.zip staging [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host [LLM] node.js process staging credential dump in nt-* temp directory [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] Credential archive staging — trin.tar.gz created by python process [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in tempArticles citing this technique (10)
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431