SOUNDBITE

S0157

Malware.View on attack.mitre.org

About this malware

SOUNDBITE is a signature backdoor used by APT32.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1010
Application Window Discovery

SOUNDBITE is capable of enumerating application windows.

T1071.004
DNS

SOUNDBITE communicates via DNS for C2.

T1082
System Information Discovery

SOUNDBITE is capable of gathering system information.

T1083
File and Directory Discovery

SOUNDBITE is capable of enumerating and manipulating files and directories.

T1112
Modify Registry

SOUNDBITE is capable of modifying the Registry.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT32 May 2017 Open source
    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.