Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTroll Stealer | Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note. |
| T1016 System Network Configuration Discovery |
MalwareGomir | Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses. |
| T1018 Remote System Discovery |
MalwareGomir | Gomir probes arbitrary network endpoints for TCP connectivity. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoBear | GoBear is installed through droppers masquerading as legitimate, signed software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTroll Stealer | Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1053.003 Cron |
MalwareGomir | Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges. |
| T1059.004 Unix Shell |
MalwareGomir | Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands. |
| T1069.001 Local Groups |
MalwareGomir | Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments. |
| T1070.004 File Deletion |
MalwareGomir | Gomir deletes its original executable and terminates its original process after creating a systemd service. |
| T1071.001 Web Protocols |
MalwareGomir | Gomir periodically communicates to its command and control infrastructure through HTTP POST requests. |
| T1082 System Information Discovery |
MalwareTroll Stealer | Troll Stealer can collect local system information. |
| T1082 System Information Discovery |
MalwareGomir | Gomir collects information on infected systems such as hostname, username, CPU, and RAM information. |
| T1083 File and Directory Discovery |
MalwareGomir | Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems. |
| T1090.001 Internal Proxy |
MalwareGomir | Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks. |
| T1113 Screen Capture |
MalwareTroll Stealer | Troll Stealer can capture screenshots from victim machines. |
| T1132.001 Standard Encoding |
MalwareGomir | Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure. |
| T1213 Data from Information Repositories |
MalwareTroll Stealer | Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems. |
| T1217 Browser Information Discovery |
MalwareTroll Stealer | Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions. |
| T1543.002 Systemd Service |
MalwareGomir | Gomir creates a systemd service named `syslogd` for persistence. |
| T1552.004 Private Keys |
MalwareTroll Stealer | Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems. |
| T1553.002 Code Signing |
MalwareGoBear | GoBear uses stolen legitimate code signing certificates for defense evasion. |
| T1573 Encrypted Channel |
MalwareGomir | Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| T1573.002 Asymmetric Cryptography |
MalwareGomir | Gomir uses reverse proxy functionality that employs SSL to encrypt communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.