RIPTIDE

S0003

Malware.View on attack.mitre.org

About this malware

RIPTIDE is a proxy-aware backdoor used by APT12.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1071.001
Web Protocols

APT12 has used RIPTIDE, a RAT that uses HTTP to communicate.

T1573.001
Symmetric Cryptography

APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Moran 2014 Open source
    Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.