Mivast

S0080

Malware.View on attack.mitre.org

About this malware

Mivast is a backdoor that has been used by Deep Panda. It was reportedly used in the Anthem breach.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1003.002
Security Account Manager

Mivast has the capability to gather NTLM password information.

T1059.003
Windows Command Shell

Mivast has the capability to open a remote shell and run basic commands.

T1105
Ingress Tool Transfer

Mivast has the capability to download and execute .exe files.

T1547.001
Registry Run Keys / Startup Folder

Mivast creates the following Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Micromedia.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Black Vine Open source
    DiMaggio, J.. (2015, August 6). The Black Vine cyberespionage group. Retrieved January 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.