Skip to content

Latest commit

 

History

History
53 lines (43 loc) · 1.32 KB

attor.md

File metadata and controls

53 lines (43 loc) · 1.32 KB
ID X0049
Type Spyware
Aliases None
Platforms X0042
Year 2013
Associated ATT&CK Software Attor

Attor

Attor is a Windows-based espionage platform used in targeted attacks since 2013. Attor has a loadable plugin architecture to customize functionality for specific targets. [1]

ATT&CK Techniques

See ATT&CK: Attor - Techniques Used.

Enhanced ATT&CK Techniques

Name Use
Exfiltration::Automated Exfiltration (E1020) Attor has a file uploader plugin that automatically exfiltrates collected data and log files to a C2 server [1]

Indicators of Compromise

SHA1 Hashes

  • 47dc997d08d53e55b8450940d9de94e2b5db631e
  • 52213cab4954c850a1ac51974a24b878ca88eb59
  • 8a6829b8615c5f6661a84ea3af0e15ab28c5840c
  • d0528b8777d556809ac64935fa6247164aaabb4f
  • f7e30a3fa186361794699d7a4fac6a9b85ccbf40

References

[1] https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Attor.pdf