Linfo

S0211

Malware.View on attack.mitre.org

About this malware

Linfo is a rootkit trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

Linfo creates a backdoor through which remote attackers can obtain data from local systems.

T1008
Fallback Channels

Linfo creates a backdoor through which remote attackers can change C2 servers.

T1029
Scheduled Transfer

Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure.

T1057
Process Discovery

Linfo creates a backdoor through which remote attackers can retrieve a list of running processes.

T1059.003
Windows Command Shell

Linfo creates a backdoor through which remote attackers can start a remote shell.

T1070.004
File Deletion

Linfo creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery

Linfo creates a backdoor through which remote attackers can retrieve system information.

T1083
File and Directory Discovery

Linfo creates a backdoor through which remote attackers can list contents of drives and search for files.

T1105
Ingress Tool Transfer

Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Linfo May 2012 Open source
    Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.