Malware.View on attack.mitre.org
Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts. |
| T1053.005 Scheduled Task |
Spica has created a scheduled task named `CalendarChecker` to establish persistence. |
| T1059.001 PowerShell |
Spica can use an obfuscated PowerShell command to create a scheduled task for persistence. |
| T1083 File and Directory Discovery |
Spica can list filesystem contents on targeted systems. |
| T1095 Non-Application Layer Protocol |
Spica can use JSON over WebSockets for C2 communications. |
| T1105 Ingress Tool Transfer |
Spica can upload and download files to and from compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document. |
| T1539 Steal Web Session Cookie |
Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers. |
| T1560 Archive Collected Data |
Spica can archive collected documents for exfiltration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.