Nidiran

S0118

Malware.View on attack.mitre.org

About this malware

Nidiran is a custom backdoor developed and used by Suckfly. It has been delivered via strategic web compromise.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1036.004
Masquerade Task or Service

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager), which mimics the legitimate Microsoft database by the same name.

T1105
Ingress Tool Transfer

Nidiran can download and execute files.

T1543.003
Windows Service

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager).

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Suckfly March 2016 Open source
    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.