Psylo

S0078

Malware.View on attack.mitre.org

About this malware

Psylo is a shellcode-based Trojan that has been used by Scarlet Mimic. It has similar characteristics as FakeM.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

Psylo exfiltrates data to its C2 server over the same protocol as C2 communications.

T1070.006
Timestomp

Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory.

T1071.001
Web Protocols

Psylo uses HTTPS for C2.

T1083
File and Directory Discovery

Psylo has commands to enumerate all storage devices and to find all files that start with a particular string.

T1105
Ingress Tool Transfer

Psylo has a command to download a file to the system from its C2 server.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Scarlet Mimic Jan 2016 Open source
    Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.