ATT&CKReferencesFysbis Palo Alto Analysis

Fysbis Palo Alto Analysis

Bryan Lee and Rob Downs. (2016, February 12). A Look Into Fysbis: Sofacy’s Linux Backdoor. Retrieved September 10, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareFysbis

Fysbis can perform keylogging.

T1059.004
Unix Shell
MalwareFysbis

Fysbis has the ability to create and execute commands in a remote shell for CLI.

T1082
System Information Discovery
MalwareFysbis

Fysbis has used the command ls /etc | egrep -e"fedora\*|debian\*|gentoo\*|mandriva\*|mandrake\*|meego\*|redhat\*|lsb-\*|sun-\*|SUSE\*|release" to determine which Linux OS version is running.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.