Fysbis

S0410

Malware.View on attack.mitre.org

About this malware

Fysbis is a Linux-based backdoor used by APT28 that dates back to at least 2014.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Fysbis has been encrypted using XOR and RC4.

T1036.004
Masquerade Task or Service

Fysbis has masqueraded as the rsyncd and dbus-inotifier services.

T1036.005
Match Legitimate Resource Name or Location

Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.

T1056.001
Keylogging

Fysbis can perform keylogging.

T1057
Process Discovery

Fysbis can collect information about running processes.

T1059.004
Unix Shell

Fysbis has the ability to create and execute commands in a remote shell for CLI.

T1070.004
File Deletion

Fysbis has the ability to delete files.

T1082
System Information Discovery

Fysbis has used the command ls /etc | egrep -e"fedora\*|debian\*|gentoo\*|mandriva\*|mandrake\*|meego\*|redhat\*|lsb-\*|sun-\*|SUSE\*|release" to determine which Linux OS version is running.

T1083
File and Directory Discovery

Fysbis has the ability to search for files.

T1132.001
Standard Encoding

Fysbis can use Base64 to encode its C2 traffic.

T1543.002
Systemd Service

Fysbis has established persistence using a systemd service.

T1547.013
XDG Autostart Entries

If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Fysbis Palo Alto Analysis Open source
    Bryan Lee and Rob Downs. (2016, February 12). A Look Into Fysbis: Sofacy’s Linux Backdoor. Retrieved September 10, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.