Umbreon

S0221

Malware.View on attack.mitre.org

About this malware

A Linux rootkit that provides backdoor access and hides from defenders.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1014
Rootkit

Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware.

T1059.003
Windows Command Shell

Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet

T1078.003
Local Accounts

Umbreon creates valid local users to provide access to the system.

T1095
Non-Application Layer Protocol

Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate.

T1205
Traffic Signaling

Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet.

Groups that use it0

None recorded.

Campaigns0

None recorded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.