Skip to content

Hide Navigation Hide TOC

THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397)

THINCRUST is a Python-based backdoor tool that has been used by UNC3886 since at least 2023.(Citation: Mandiant Fortinet Zero Day)

Cluster A Galaxy A Cluster B Galaxy B Level
Symmetric Cryptography - T1573.001 (24bfaeba-cb0d-4525-b3dc-507c77ecec41) Attack Pattern THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware 1
THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware Python - T1059.006 (cc3502b5-30cc-4473-ad48-42d51a6ef6d1) Attack Pattern 1
Deobfuscate/Decode Files or Information - T1140 (3ccef7ae-cb5e-48f6-8302-897105fbf55c) Attack Pattern THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware 1
THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware Disable or Modify System Firewall - T1562.004 (5372c5fe-f424-4def-bcd5-d3a8e770f07b) Attack Pattern 1
THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern 1
Symmetric Cryptography - T1573.001 (24bfaeba-cb0d-4525-b3dc-507c77ecec41) Attack Pattern Encrypted Channel - T1573 (b8902400-e6c5-4ba2-95aa-2d35b442b118) Attack Pattern 2
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Python - T1059.006 (cc3502b5-30cc-4473-ad48-42d51a6ef6d1) Attack Pattern 2
Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern Disable or Modify System Firewall - T1562.004 (5372c5fe-f424-4def-bcd5-d3a8e770f07b) Attack Pattern 2
Application Layer Protocol - T1071 (355be19c-ffc9-46d5-8d50-d6a036c675b6) Attack Pattern Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern 2