ATT&CKSoftwareBlackMould

BlackMould

S0564

Malware.View on attack.mitre.org

About this malware

BlackMould is a web shell based on China Chopper for servers running Microsoft IIS. First reported in December 2019, it has been used in malicious campaigns by GALLIUM against telecommunication providers.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1005
Data from Local System

BlackMould can copy files on a compromised host.

T1059.003
Windows Command Shell

BlackMould can run cmd.exe with parameters.

T1071.001
Web Protocols

BlackMould can send commands to C2 in the body of HTTP POST requests.

T1083
File and Directory Discovery

BlackMould has the ability to find files on the targeted system.

T1105
Ingress Tool Transfer

BlackMould has the ability to download files to the victim's machine.

T1680
Local Storage Discovery

BlackMould can enumerate local drives on a compromised host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft GALLIUM December 2019 Open source
    MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.