GRIFFON

S0417

Malware.View on attack.mitre.org

About this malware

GRIFFON is a JavaScript backdoor used by FIN7.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1053.005
Scheduled Task

GRIFFON has used sctasks for persistence.

T1059.001
PowerShell

GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet.

T1059.007
JavaScript

GRIFFON is written in and executed as JavaScript.

T1069.002
Domain Groups

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.

T1082
System Information Discovery

GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .

T1113
Screen Capture

GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system.

T1124
System Time Discovery

GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system.

T1547.001
Registry Run Keys / Startup Folder

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SecureList Griffon May 2019 Open source
    Namestnikov, Y. and Aime, F. (2019, May 8). FIN7.5: the infamous cybercrime rig “FIN7” continues its activities. Retrieved October 11, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.