ATT&CKReferencesUmbreon Trend Micro

Umbreon Trend Micro

Fernando Mercês. (2016, September 5). Pokémon-themed Umbreon Linux Rootkit Hits x86, ARM Systems. Retrieved March 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareUmbreon

Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware.

T1059.003
Windows Command Shell
MalwareUmbreon

Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet

T1078.003
Local Accounts
MalwareUmbreon

Umbreon creates valid local users to provide access to the system.

T1095
Non-Application Layer Protocol
MalwareUmbreon

Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate.

T1205
Traffic Signaling
MalwareUmbreon

Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.