S-Type

S0085

Malware.View on attack.mitre.org

About this malware

S-Type is a backdoor that was used in Operation Dust Storm since at least 2013.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1007
System Service Discovery

S-Type runs the command net start on a victim.

T1008
Fallback Channels

S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails.

T1016
System Network Configuration Discovery

S-Type has used `ipconfig /all` on a compromised host.

T1027.002
Software Packing

Some S-Type samples have been packed with UPX.

T1033
System Owner/User Discovery

S-Type has run tests to determine the privilege level of the compromised user.

T1036.005
Match Legitimate Resource Name or Location

S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel

S-Type has uploaded data and files from a compromised host to its C2 servers.

T1059.003
Windows Command Shell

S-Type has provided the ability to execute shell commands on a compromised host.

T1070.004
File Deletion

S-Type has deleted files it has created on a compromised host.

T1070.009
Clear Persistence

S-Type has deleted accounts it has created.

T1071.001
Web Protocols

S-Type uses HTTP for C2.

T1082
System Information Discovery

The initial beacon packet for S-Type contains the operating system version and file system of the victim.

T1087.001
Local Account

S-Type has run the command `net user` on a victim.

T1105
Ingress Tool Transfer

S-Type can download additional files onto a compromised host.

T1106
Native API

S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`.

View all 20 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.