metaMain

S1059

Malware.View on attack.mitre.org

About this malware

metaMain is a backdoor used by Metador to maintain long-term access to compromised machines; it has also been used to decrypt Mafalda into memory.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1005
Data from Local System

metaMain can collect files and system information from a compromised host.

T1027.013
Encrypted/Encoded File

metaMain's module file has been encrypted via XOR.

T1033
System Owner/User Discovery

metaMain can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel

metaMain can upload collected files and data to its C2 server.

T1055
Process Injection

metaMain can inject the loader file, Speech02.db, into a process.

T1056
Input Capture

metaMain can log mouse events.

T1056.001
Keylogging

metaMain has the ability to log keyboard events.

T1057
Process Discovery

metaMain can enumerate the processes that run on the platform.

T1070.004
File Deletion

metaMain has deleted collected items after uploading the content to its C2 server.

T1070.006
Timestomp

metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges.

T1071.001
Web Protocols

metaMain can use HTTP for C2 communications.

T1074.001
Local Data Staging

metaMain has stored the collected system files in a working directory.

T1082
System Information Discovery

metaMain can collect the computer name from a compromised host.

T1083
File and Directory Discovery

metaMain can recursively enumerate files in an operator-provided directory.

T1090.001
Internal Proxy

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. SentinelLabs Metador Sept 2022 Open source
    Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.
  2. SentinelLabs Metador Technical Appendix Sept 2022 Open source
    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.