Skip to content

S0156 KOMPROGO

KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management. 1

Item Value
ID S0156
Associated Names
Type MALWARE
Version 1.1
Created 14 December 2017
Last Modified 30 March 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.003 Windows Command Shell KOMPROGO is capable of creating a reverse shell.1
enterprise T1082 System Information Discovery KOMPROGO is capable of retrieving information about the infected system.1
enterprise T1047 Windows Management Instrumentation KOMPROGO is capable of running WMI queries.1

Groups That Use This Software

ID Name References
G0050 APT32 1

References