Malware.View on attack.mitre.org
RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.
| Technique | Procedure example |
|---|---|
| T1059.004 Unix Shell |
RIFLESPINE can execute commands with `/bin/sh`. |
| T1071.001 Web Protocols |
RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files. |
| T1074.001 Local Data Staging |
RIFLESPINE can stage the output from executed C2 commands to a temporary file. |
| T1082 System Information Discovery |
RIFLESPINE can collect system information after installation on infected systems. |
| T1102.002 Bidirectional Communication |
RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive. |
| T1105 Ingress Tool Transfer |
RIFLESPINE can download and execute files. |
| T1140 Deobfuscate/Decode Files or Information |
RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts. |
| T1543.002 Systemd Service |
RIFLESPINE can create a systemd service file for execution. |
| T1567.002 Exfiltration to Cloud Storage |
RIFLESPINE can upload results from executed C2 commands to cloud storage. |
| T1573.001 Symmetric Cryptography |
RIFLESPINE can use the AES algorithm to encrypt C2 data. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.