Malware.View on attack.mitre.org
ZIPLINE is a passive backdoor that was used during Cutting Edge on compromised Secure Connect VPNs for reverse shell and proxy functionality.
| Technique | Procedure example |
|---|---|
| T1057 Process Discovery |
ZIPLINE can identify running processes and their names. |
| T1059.004 Unix Shell |
ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands. |
| T1083 File and Directory Discovery |
ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands. |
| T1090 Proxy |
ZIPLINE can create a proxy server on compromised hosts. |
| T1095 Non-Application Layer Protocol |
ZIPLINE can communicate with C2 using a custom binary protocol. |
| T1105 Ingress Tool Transfer |
ZIPLINE can download files to be saved on the compromised system. |
| T1205 Traffic Signaling |
ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality. |
| T1573.001 Symmetric Cryptography |
ZIPLINE can use AES-128-CBC to encrypt data for both upload and download. |
| T1685 Disable or Modify Tools |
ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.