Dipsind

S0200

Malware.View on attack.mitre.org

About this malware

Dipsind is a malware family of backdoors that appear to be used exclusively by PLATINUM.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1029
Scheduled Transfer

Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic.

T1059.003
Windows Command Shell

Dipsind can spawn remote shells.

T1071.001
Web Protocols

Dipsind uses HTTP for C2.

T1105
Ingress Tool Transfer

Dipsind can download remote files.

T1132.001
Standard Encoding

Dipsind encodes C2 traffic with base64.

T1547.004
Winlogon Helper DLL

A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence.

T1573.001
Symmetric Cryptography

Dipsind encrypts C2 data with AES256 in ECB mode.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft PLATINUM April 2016 Open source
    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.