Naid

S0205

Malware.View on attack.mitre.org

About this malware

Naid is a trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1016
System Network Configuration Discovery

Naid collects the domain name from a compromised host.

T1082
System Information Discovery

Naid collects a unique identifier (UID) from a compromised host.

T1112
Modify Registry

Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk.

T1543.003
Windows Service

Naid creates a new service to establish.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Naid June 2012 Open source
    Neville, A. (2012, June 15). Trojan.Naid. Retrieved February 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.