Briba

S0204

Malware.View on attack.mitre.org

About this malware

Briba is a trojan used by Elderwood to open a backdoor and download files on to compromised hosts.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1105
Ingress Tool Transfer

Briba downloads files onto infected hosts.

T1218.011
Rundll32

Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs.

T1543.003
Windows Service

Briba installs a service pointing to a malicious DLL dropped to disk.

T1547.001
Registry Run Keys / Startup Folder

Briba creates run key Registry entries pointing to malicious DLLs dropped to disk.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Briba May 2012 Open source
    Ladley, F. (2012, May 15). Backdoor.Briba. Retrieved February 21, 2018.
  2. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.