Skip to content

S0202 adbupd

adbupd is a backdoor used by PLATINUM that is similar to Dipsind. 1

Item Value
ID S0202
Associated Names
Type MALWARE
Version 1.1
Created 18 April 2018
Last Modified 30 March 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.003 Windows Command Shell adbupd can run a copy of cmd.exe.1
enterprise T1573 Encrypted Channel -
enterprise T1573.002 Asymmetric Cryptography adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.1
enterprise T1546 Event Triggered Execution -
enterprise T1546.003 Windows Management Instrumentation Event Subscription adbupd can use a WMI script to achieve persistence.1

Groups That Use This Software

ID Name References
G0068 PLATINUM 1

References