PHOREAL

S0158

Malware.View on attack.mitre.org

About this malware

PHOREAL is a signature backdoor used by APT32.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

PHOREAL is capable of creating reverse shell.

T1095
Non-Application Layer Protocol

PHOREAL communicates via ICMP for C2.

T1112
Modify Registry

PHOREAL is capable of manipulating the Registry.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT32 May 2017 Open source
    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.