THINCRUST

S1223

Malware.View on attack.mitre.org

About this malware

THINCRUST is a Python-based backdoor tool that has been used by UNC3886 since at least 2023.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.006
Python

THINCRUST can use Python scripts for command execution.

T1071.001
Web Protocols

THINCRUST can use HTTP POST requests in C2 communications.

T1140
Deobfuscate/Decode Files or Information

THINCRUST can deobfuscate RSA encrypted C2 commands received through the DEVICEID cookie.

T1573.001
Symmetric Cryptography

THINCRUST can process RSA encryted C2 commands.

T1686
Disable or Modify System Firewall

THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Fortinet Zero Day Open source
    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.