REPTILE

S1219

Malware.View on attack.mitre.org

About this malware

REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1014
Rootkit

REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections.

T1059.004
Unix Shell

REPTILE can deploy components automatically with shell scripts.

T1095
Non-Application Layer Protocol

REPTILE can communicate using TLS over raw TCP.

T1140
Deobfuscate/Decode Files or Information

The REPTILE launcher component can decrypt kernel module code from a file and load it into memory.

T1205
Traffic Signaling

The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation.

T1205.001
Port Knocking

REPTILE has the ability to control compromised endpoints via port knocking.

T1543.004
Launch Daemon

The REPTILE launcher can daemonize a process.

T1546.017
Udev Rules

REPTILE has used udev for persistence.

T1547.006
Kernel Modules and Extensions

The REPTILE rootkit is implemented as a loadable kernel module (LKM).

T1564.001
Hidden Files and Directories

REPTILE has the ability to communicate with the kernel-mode component to hide files.

T1573.002
Asymmetric Cryptography

REPTILE can use TLS over raw TCP for secure C2.

Groups that use it1

Campaigns1

References1

  1. Google Cloud Mandiant UNC3886 2024 Open source
    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.