QUIETEXIT

S1084

Malware.View on attack.mitre.org

About this malware

QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least 2021. APT29 has deployed QUIETEXIT on opaque network appliances that typically don't support antivirus or endpoint detection and response tools within a victim environment.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1008
Fallback Channels

QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails.

T1036.005
Match Legitimate Resource Name or Location

QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files.

T1071
Application Layer Protocol

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

T1090.002
External Proxy

QUIETEXIT can proxy traffic via SOCKS.

T1095
Non-Application Layer Protocol

QUIETEXIT can establish a TCP connection as part of its initial connection to the C2.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT29 Eye Spy Email Nov 22 Open source
    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.