Skip to content

S1000 ACAD/Medre.A

ACAD/Medre.A is a worm that steals operational information. The worm collects AutoCAD files with drawings. ACAD/Medre.A has the capability to be used for industrial espionage.1

Item Value
ID S1000
Associated Names
Version 1.0
Created 31 May 2017
Last Modified 12 October 2022
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
ics T0893 Data from Local System ACAD/Medre.A collects information related to the AutoCAD application. The worm collects AutoCAD (*.dwg) files with drawings from infected systems. 1
ics T0882 Theft of Operational Information ACAD/Medre.A can collect AutoCad files with drawings. These drawings may contain operational information. 1