Malware.View on attack.mitre.org
S-Type is a backdoor that was used in Operation Dust Storm since at least 2013.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
S-Type runs the command |
| T1008 Fallback Channels |
S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails. |
| T1016 System Network Configuration Discovery |
S-Type has used `ipconfig /all` on a compromised host. |
| T1027.002 Software Packing |
Some S-Type samples have been packed with UPX. |
| T1033 System Owner/User Discovery |
S-Type has run tests to determine the privilege level of the compromised user. |
| T1036.005 Match Legitimate Resource Name or Location |
S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1041 Exfiltration Over C2 Channel |
S-Type has uploaded data and files from a compromised host to its C2 servers. |
| T1059.003 Windows Command Shell |
S-Type has provided the ability to execute shell commands on a compromised host. |
| T1070.004 File Deletion |
S-Type has deleted files it has created on a compromised host. |
| T1070.009 Clear Persistence |
S-Type has deleted accounts it has created. |
| T1071.001 Web Protocols |
S-Type uses HTTP for C2. |
| T1082 System Information Discovery |
The initial beacon packet for S-Type contains the operating system version and file system of the victim. |
| T1087.001 Local Account |
S-Type has run the command `net user` on a victim. |
| T1105 Ingress Tool Transfer |
S-Type can download additional files onto a compromised host. |
| T1106 Native API |
S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.