Malware.View on attack.mitre.org
SpeakUp is a Trojan backdoor that targets both Linux and OSX devices. It was first observed in January 2019.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
SpeakUp uses the |
| T1027.013 Encrypted/Encoded File |
SpeakUp encodes its second-stage payload with Base64. |
| T1033 System Owner/User Discovery |
SpeakUp uses the |
| T1046 Network Service Discovery |
SpeakUp checks for availability of specific ports on servers. |
| T1049 System Network Connections Discovery |
SpeakUp uses the |
| T1053.003 Cron |
SpeakUp uses cron tasks to ensure persistence. |
| T1059 Command and Scripting Interpreter |
SpeakUp uses Perl scripts. |
| T1059.006 Python |
SpeakUp uses Python scripts. |
| T1070.004 File Deletion |
SpeakUp deletes files to remove evidence on the machine. |
| T1071.001 Web Protocols |
SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server. |
| T1082 System Information Discovery |
SpeakUp uses the |
| T1105 Ingress Tool Transfer |
SpeakUp downloads and executes additional files from a remote server. |
| T1110.001 Password Guessing |
SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels. |
| T1132.001 Standard Encoding |
SpeakUp encodes C&C communication using Base64. |
| T1203 Exploitation for Client Execution |
SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.