ELMER

S0064

Malware.View on attack.mitre.org

About this malware

ELMER is a non-persistent, proxy-aware HTTP backdoor written in Delphi that has been used by APT16.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1057
Process Discovery

ELMER is capable of performing process listings.

T1071.001
Web Protocols

ELMER uses HTTP for command and control.

T1083
File and Directory Discovery

ELMER is capable of performing directory listings.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye EPS Awakens Part 2 Open source
    Winters, R. (2015, December 20). The EPS Awakens - Part 2. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.