S0416Windows

S0416RDFSNIFFER

Platforms
1
ATT&CK
14.1
References
2

Description

[RDFSNIFFER](https://attack.mitre.org/software/S0416) is a module loaded by [BOOSTWRITE](https://attack.mitre.org/software/S0415) which allows an attacker to monitor and tamper with legitimate connections made via an application designed to provide visibility and system management capabilities to remote IT techs.(Citation: FireEye FIN7 Oct 2019)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0416
  2. https://www.fireeye.com/blog/threat-research/2019/10/mahalo-fin7-responding-to-new-tools-and-techniques.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
BOOSTWRITE
Software
RDAT
Software
Rifdoor
Software
SDBbot
Software
ShimRatReporter
Software
Ramsay
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.