Wiarp

S0206

Malware.View on attack.mitre.org

About this malware

Wiarp is a trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1055
Process Injection

Wiarp creates a backdoor through which remote attackers can inject files into running processes.

T1059.003
Windows Command Shell

Wiarp creates a backdoor through which remote attackers can open a command line interface.

T1105
Ingress Tool Transfer

Wiarp creates a backdoor through which remote attackers can download files.

T1543.003
Windows Service

Wiarp creates a backdoor through which remote attackers can create a service.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Wiarp May 2012 Open source
    Zhou, R. (2012, May 15). Backdoor.Wiarp. Retrieved February 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.