Sys10

S0060

Malware.View on attack.mitre.org

About this malware

Sys10 is a backdoor that was used throughout 2013 by Naikon.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1016
System Network Configuration Discovery

Sys10 collects the local IP address of the victim and sends it to the C2.

T1033
System Owner/User Discovery

Sys10 collects the account name of the logged-in user and sends it to the C2.

T1069.001
Local Groups

Sys10 collects the group name of the logged-in user and sends it to the C2.

T1071.001
Web Protocols

Sys10 uses HTTP for C2.

T1082
System Information Discovery

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.

T1573.001
Symmetric Cryptography

Sys10 uses an XOR 0x1 loop to encrypt its C2 domain.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Baumgartner Naikon 2015 Open source
    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.