SNUGRIDE

S0159

Malware.View on attack.mitre.org

About this malware

SNUGRIDE is a backdoor that has been used by menuPass as first stage malware.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.003
Windows Command Shell

SNUGRIDE is capable of executing commands and spawning a reverse shell.

T1071.001
Web Protocols

SNUGRIDE communicates with its C2 server over HTTP.

T1547.001
Registry Run Keys / Startup Folder

SNUGRIDE establishes persistence through a Registry Run key.

T1573.001
Symmetric Cryptography

SNUGRIDE encrypts C2 traffic using AES with a static key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT10 April 2017 Open source
    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.