TEXTMATE

S0146

Malware.View on attack.mitre.org

About this malware

TEXTMATE is a second-stage PowerShell backdoor that is memory-resident. It was observed being used along with POWERSOURCE in February 2017.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1059.003
Windows Command Shell

TEXTMATE executes cmd.exe to provide a reverse shell to adversaries.

T1071.004
DNS

TEXTMATE uses DNS TXT records for C2.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye FIN7 March 2017 Open source
    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.