ATT&CKSoftwareRIFLESPINE

RIFLESPINE

S1222

Malware.View on attack.mitre.org

About this malware

RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1059.004
Unix Shell

RIFLESPINE can execute commands with `/bin/sh`.

T1071.001
Web Protocols

RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files.

T1074.001
Local Data Staging

RIFLESPINE can stage the output from executed C2 commands to a temporary file.

T1082
System Information Discovery

RIFLESPINE can collect system information after installation on infected systems.

T1102.002
Bidirectional Communication

RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.

T1105
Ingress Tool Transfer

RIFLESPINE can download and execute files.

T1140
Deobfuscate/Decode Files or Information

RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts.

T1543.002
Systemd Service

RIFLESPINE can create a systemd service file for execution.

T1567.002
Exfiltration to Cloud Storage

RIFLESPINE can upload results from executed C2 commands to cloud storage.

T1573.001
Symmetric Cryptography

RIFLESPINE can use the AES algorithm to encrypt C2 data.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google Cloud Mandiant UNC3886 2024 Open source
    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.