Malware.View on attack.mitre.org
Mivast is a backdoor that has been used by Deep Panda. It was reportedly used in the Anthem breach.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
Mivast has the capability to gather NTLM password information. |
| T1059.003 Windows Command Shell |
Mivast has the capability to open a remote shell and run basic commands. |
| T1105 Ingress Tool Transfer |
Mivast has the capability to download and execute .exe files. |
| T1547.001 Registry Run Keys / Startup Folder |
Mivast creates the following Registry entry: |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.