adbupd

S0202

Malware.View on attack.mitre.org

About this malware

adbupd is a backdoor used by PLATINUM that is similar to Dipsind.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

adbupd can run a copy of cmd.exe.

T1546.003
Windows Management Instrumentation Event Subscription

adbupd can use a WMI script to achieve persistence.

T1573.002
Asymmetric Cryptography

adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft PLATINUM April 2016 Open source
    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.