Malware.View on attack.mitre.org
A Linux rootkit that provides backdoor access and hides from defenders.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware. |
| T1059.003 Windows Command Shell |
Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet |
| T1078.003 Local Accounts |
Umbreon creates valid local users to provide access to the system. |
| T1095 Non-Application Layer Protocol |
Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate. |
| T1205 Traffic Signaling |
Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.