FYAnti

S0628

Malware.View on attack.mitre.org

About this malware

FYAnti is a loader that has been used by menuPass since at least 2020, including to deploy QuasarRAT.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1027.002
Software Packing

FYAnti has used ConfuserEx to pack its .NET module.

T1083
File and Directory Discovery

FYAnti can search the C:\Windows\Microsoft.NET\ directory for files of a specified size.

T1105
Ingress Tool Transfer

FYAnti can download additional payloads to a compromised host.

T1140
Deobfuscate/Decode Files or Information

FYAnti has the ability to decrypt an embedded .NET module.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Securelist APT10 March 2021 Open source
    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.