ATT&CKSoftwareTINYTYPHON

TINYTYPHON

S0131

Malware.View on attack.mitre.org

About this malware

TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1020
Automated Exfiltration

When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.

T1027.013
Encrypted/Encoded File

TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file.

T1083
File and Directory Discovery

TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions.

T1547.001
Registry Run Keys / Startup Folder

TINYTYPHON installs itself under Registry Run key to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Forcepoint Monsoon Open source
    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.