Malware.View on attack.mitre.org
REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections. |
| T1059.004 Unix Shell |
REPTILE can deploy components automatically with shell scripts. |
| T1095 Non-Application Layer Protocol |
REPTILE can communicate using TLS over raw TCP. |
| T1140 Deobfuscate/Decode Files or Information |
The REPTILE launcher component can decrypt kernel module code from a file and load it into memory. |
| T1205 Traffic Signaling |
The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation. |
| T1205.001 Port Knocking |
REPTILE has the ability to control compromised endpoints via port knocking. |
| T1543.004 Launch Daemon |
The REPTILE launcher can daemonize a process. |
| T1546.017 Udev Rules |
REPTILE has used udev for persistence. |
| T1547.006 Kernel Modules and Extensions |
The REPTILE rootkit is implemented as a loadable kernel module (LKM). |
| T1564.001 Hidden Files and Directories |
REPTILE has the ability to communicate with the kernel-mode component to hide files. |
| T1573.002 Asymmetric Cryptography |
REPTILE can use TLS over raw TCP for secure C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.