Archive Collected Data: Archive via Custom Method

Threat Actors may compress or encrypt data that is collected prior to exfiltration using a custom method. Threat Actors may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.

ID: ATAGS-T1167.003
Sub-technique of:  ATAGS-T1167
Tactic: Collection
Targeted Components: Software
Responsibility: Shared
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.