Malware.View on attack.mitre.org
TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm.
| Technique | Procedure example |
|---|---|
| T1020 Automated Exfiltration |
When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server. |
| T1027.013 Encrypted/Encoded File |
TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file. |
| T1083 File and Directory Discovery |
TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions. |
| T1547.001 Registry Run Keys / Startup Folder |
TINYTYPHON installs itself under Registry Run key to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.