Mafalda

S1060

Malware.View on attack.mitre.org

About this malware

Mafalda is a flexible interactive implant that has been used by Metador. Security researchers assess the Mafalda name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1003.001
LSASS Memory

Mafalda can dump password hashes from `LSASS.exe`.

T1005
Data from Local System

Mafalda can collect files and information from a compromised host.

T1012
Query Registry

Mafalda can enumerate Registry keys with all subkeys and values.

T1016
System Network Configuration Discovery

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.

T1027.013
Encrypted/Encoded File

Mafalda has been obfuscated and contains encrypted functions.

T1033
System Owner/User Discovery

Mafalda can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel

Mafalda can send network system data and files to its C2 server.

T1049
System Network Connections Discovery

Mafalda can use the GetExtendedTcpTable function to retrieve information about established TCP connections.

T1056
Input Capture

Mafalda can conduct mouse event logging.

T1057
Process Discovery

Mafalda can enumerate running processes on a machine.

T1059.001
PowerShell

Mafalda can execute PowerShell commands on a compromised machine.

T1059.003
Windows Command Shell

Mafalda can execute shell commands using `cmd.exe`.

T1071.001
Web Protocols

Mafalda can use HTTP for C2.

T1074.001
Local Data Staging

Mafalda can place retrieved files into a destination directory.

T1082
System Information Discovery

Mafalda can collect the computer name of a compromised host.

View all 36 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelLabs Metador Sept 2022 Open source
    Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.