ATT&CKSoftwareFlawedGrace

FlawedGrace

S0383

Malware.View on attack.mitre.org

About this malware

FlawedGrace is a fully featured remote access tool (RAT) written in C++ that was first observed in late 2017.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

FlawedGrace encrypts its C2 configuration files with AES in CBC mode.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Proofpoint TA505 Jan 2019 Open source
    Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.