Malware.View on attack.mitre.org
PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file read/write.
| Technique | Procedure example |
|---|---|
| T1059.004 Unix Shell |
PITSTOP has the ability to receive shell commands over a Unix domain socket. |
| T1140 Deobfuscate/Decode Files or Information |
PITSTOP can deobfuscate base64 encoded and AES encrypted commands. |
| T1205.002 Socket Filters |
PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS. |
| T1559 Inter-Process Communication |
PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`. |
| T1573.002 Asymmetric Cryptography |
PITSTOP has the ability to communicate over TLS. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.