Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. RIFLESPINE

RIFLESPINE

RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.[1]

ID: S1222
Type: MALWARE
Platforms: Linux
Version: 1.0
Created: 12 June 2025
Last Modified: 12 June 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

RIFLESPINE can use HTTPGET andPUT to upload and download files.[1]

EnterpriseT1059.004Command and Scripting Interpreter:Unix Shell

RIFLESPINE can execute commands with/bin/sh.[1]

EnterpriseT1543.002Create or Modify System Process:Systemd Service

RIFLESPINE can create a systemd service file for execution.[1]

EnterpriseT1074.001Data Staged:Local Data Staging

RIFLESPINE can stage the output from executed C2 commands to a temporary file.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts.[1]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

RIFLESPINE can use the AES algorithm to encrypt C2 data.[1]

EnterpriseT1567.002Exfiltration Over Web Service:Exfiltration to Cloud Storage

RIFLESPINE can upload results from executed C2 commands to cloud storage.[1]

EnterpriseT1105Ingress Tool Transfer

RIFLESPINE can download and execute files.[1]

EnterpriseT1082System Information Discovery

RIFLESPINE can collect system information after installation on infected systems.[1]

EnterpriseT1102.002Web Service:Bidirectional Communication

RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.[1]

Groups That Use This Software

IDNameReferences
G1048UNC3886

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp