
ACAD/Medre.A has the capability to be used for industrial espionage.Īction RAT is a remote access tool written in Delphi that has been used by SideCopy since at least December 2021 against Indian and Afghani government personnel.Īdbupd is a backdoor used by PLATINUM that is similar to Dipsind.ĪdFind is a free command-line query tool that can be used for gathering information from Active Directory.Īdups is software that was pre-installed onto Android devices, including those made by BLU Products. The worm collects AutoCAD files with drawings. AbstractEmu was observed primarily impacting users in the United States, however victims are believed to be across a total of 17 countries.ĪCAD/Medre.A is a worm that steals operational information. It was discovered in 19 Android applications, of which at least 7 abused known Android exploits for obtaining root permissions. The tool is publicly available on GitHub.ĪBK is a downloader that has been used by BRONZE BUTLER since at least 2019.ĪbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021. Examples include PlugX, CHOPSTICK, etc.ģPARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda.ĤH RAT is malware that has been used by Putter Panda since at least 2007.ĪADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory. Malware - Commercial, custom closed source, or open source software intended to be used for malicious purposes by adversaries.

Examples include PsExec, Metasploit, Mimikatz, as well as Windows utilities such as Net, netstat, Tasklist, etc. This category includes both software that generally is not found on an enterprise system as well as software generally available as part of an operating system that is already present in an environment.

Tracking the same set of software by different names.

Some instances of software have multiple names associated with the same instance due to various organizations Or other tools used to conduct behavior modeled in ATT&CK. Software is a generic term for custom or commercial code, operating system utilities, open-source software,
