ATT&CKSoftwareWINDSHIELD

WINDSHIELD

S0155

Malware.View on attack.mitre.org

About this malware

WINDSHIELD is a signature backdoor used by APT32.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1012
Query Registry

WINDSHIELD can gather Registry values.

T1033
System Owner/User Discovery

WINDSHIELD can gather the victim user name.

T1070.004
File Deletion

WINDSHIELD is capable of file deletion along with other file system interaction.

T1082
System Information Discovery

WINDSHIELD can gather the victim computer name.

T1095
Non-Application Layer Protocol

WINDSHIELD C2 traffic can communicate via TCP raw sockets.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT32 May 2017 Open source
    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.