Fernando Mercês. (2016, September 5). Pokémon-themed Umbreon Linux Rootkit Hits x86, ARM Systems. Retrieved March 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareUmbreon | Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware. |
| T1059.003 Windows Command Shell |
MalwareUmbreon | Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet |
| T1078.003 Local Accounts |
MalwareUmbreon | Umbreon creates valid local users to provide access to the system. |
| T1095 Non-Application Layer Protocol |
MalwareUmbreon | Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate. |
| T1205 Traffic Signaling |
MalwareUmbreon | Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.