Felismus

S0171

Malware.View on attack.mitre.org

About this malware

Felismus is a modular backdoor that has been used by Sowbug.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1016
System Network Configuration Discovery

Felismus collects the victim LAN IP address and sends it to the C2 server.

T1033
System Owner/User Discovery

Felismus collects the current username and sends it to the C2 server.

T1036.005
Match Legitimate Resource Name or Location

Felismus has masqueraded as legitimate Adobe Content Management System files.

T1059.003
Windows Command Shell

Felismus uses command line for execution.

T1071.001
Web Protocols

Felismus uses HTTP for C2.

T1082
System Information Discovery

Felismus collects the system information, including hostname and OS version, and sends it to the C2 server.

T1105
Ingress Tool Transfer

Felismus can download files from remote servers.

T1132.001
Standard Encoding

Some Felismus samples use a custom method for C2 traffic that utilizes Base64.

T1518.001
Security Software Discovery

Felismus checks for processes associated with anti-virus vendors.

T1573.001
Symmetric Cryptography

Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Forcepoint Felismus Mar 2017 Open source
    Somerville, L. and Toro, A. (2017, March 30). Playing Cat & Mouse: Introducing the Felismus Malware. Retrieved November 16, 2017.
  2. Symantec Sowbug Nov 2017 Open source
    Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.