Skip to content

S1222 RIFLESPINE

RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.1

Item Value
ID S1222
Associated Names
Type MALWARE
Version 1.0
Created 12 June 2025
Last Modified 12 June 2025
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1071 Application Layer Protocol -
enterprise T1071.001 Web Protocols RIFLESPINE can use HTTP GET and PUT to upload and download files.1
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.004 Unix Shell RIFLESPINE can execute commands with /bin/sh.1
enterprise T1543 Create or Modify System Process -
enterprise T1543.002 Systemd Service RIFLESPINE can create a systemd service file for execution.1
enterprise T1074 Data Staged -
enterprise T1074.001 Local Data Staging RIFLESPINE can stage the output from executed C2 commands to a temporary file.1
enterprise T1140 Deobfuscate/Decode Files or Information RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts.1
enterprise T1573 Encrypted Channel -
enterprise T1573.001 Symmetric Cryptography RIFLESPINE can use the AES algorithm to encrypt C2 data.1
enterprise T1567 Exfiltration Over Web Service -
enterprise T1567.002 Exfiltration to Cloud Storage RIFLESPINE can upload results from executed C2 commands to cloud storage.1
enterprise T1105 Ingress Tool Transfer RIFLESPINE can download and execute files.1
enterprise T1082 System Information Discovery RIFLESPINE can collect system information after installation on infected systems.1
enterprise T1102 Web Service -
enterprise T1102.002 Bidirectional Communication RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.1

Groups That Use This Software

ID Name References
G1048 UNC3886 1

References