MOPSLED

S1221

Malware.View on attack.mitre.org

About this malware

MOPSLED is a shellcode-based modular backdoor that has been used by China-nexus cyber espionage actors including UNC3886 and APT41.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

MOPSLED can encrypt configuration files with a custom ChaCha20 algorithm.

T1071.001
Web Protocols

MOPSLED can communicate to C2 nodes over HTTP.

T1095
Non-Application Layer Protocol

MOPSLED can use a custom binary protocol over TCP for C2 communication.

T1102
Web Service

MOPSLED can use third-party web services such as GitHub and Google Drive for C2.

T1102.001
Dead Drop Resolver

MOPSLED has the ability to retrieve a C2 address from a dead drop URL.

T1140
Deobfuscate/Decode Files or Information

MOPSLED can decrypt obfuscated configuration files.

Groups that use it2

Campaigns0

None recorded.

References1

  1. Google Cloud Mandiant UNC3886 2024 Open source
    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.