ATT&CKSoftwareRDFSNIFFER

RDFSNIFFER

S0416

Malware.View on attack.mitre.org

About this malware

RDFSNIFFER is a module loaded by BOOSTWRITE which allows an attacker to monitor and tamper with legitimate connections made via an application designed to provide visibility and system management capabilities to remote IT techs.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1056.004
Credential API Hooking

RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface.

T1070.004
File Deletion

RDFSNIFFER has the capability of deleting local files.

T1106
Native API

RDFSNIFFER has used several Win32 API functions to interact with the victim machine.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye FIN7 Oct 2019 Open source
    Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.