Skip to content

S0206 Wiarp

Wiarp is a trojan used by Elderwood to open a backdoor on compromised hosts. 1 2

Item Value
ID S0206
Associated Names
Type MALWARE
Version 1.1
Created 18 April 2018
Last Modified 06 January 2021
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.003 Windows Command Shell Wiarp creates a backdoor through which remote attackers can open a command line interface.2
enterprise T1543 Create or Modify System Process -
enterprise T1543.003 Windows Service Wiarp creates a backdoor through which remote attackers can create a service.2
enterprise T1105 Ingress Tool Transfer Wiarp creates a backdoor through which remote attackers can download files.2
enterprise T1055 Process Injection Wiarp creates a backdoor through which remote attackers can inject files into running processes.2

Groups That Use This Software

ID Name References
G0066 Elderwood 1

References