POORAIM

S0216

Malware.View on attack.mitre.org

About this malware

POORAIM is a backdoor used by APT37 in campaigns since at least 2014.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1057
Process Discovery

POORAIM can enumerate processes.

T1082
System Information Discovery

POORAIM can identify system information, including battery status.

T1083
File and Directory Discovery

POORAIM can conduct file browsing.

T1102.002
Bidirectional Communication

POORAIM has used AOL Instant Messenger for C2.

T1113
Screen Capture

POORAIM can perform screen capturing.

T1189
Drive-by Compromise

POORAIM has been delivered through compromised sites acting as watering holes.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.