BS2005

S0014

Malware.View on attack.mitre.org

About this malware

BS2005 is malware that was used by Ke3chang in spearphishing campaigns since at least 2011.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1132.001
Standard Encoding

BS2005 uses Base64 encoding for communication in the message body of an HTTP request.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Mandiant Operation Ke3chang November 2014 Open source
    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.