Skip to content

Hide Navigation Hide TOC

THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397)

THINCRUST is a Python-based backdoor tool that has been used by UNC3886 since at least 2023.(Citation: Mandiant Fortinet Zero Day)

Cluster A Galaxy A Cluster B Galaxy B Level
Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware 1
Python - T1059.006 (cc3502b5-30cc-4473-ad48-42d51a6ef6d1) Attack Pattern THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware 1
Disable or Modify System Firewall - T1686 (eec096b8-c207-43df-b6c1-11523861e452) Attack Pattern THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware 1
THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware Symmetric Cryptography - T1573.001 (24bfaeba-cb0d-4525-b3dc-507c77ecec41) Attack Pattern 1
THINCRUST - S1223 (351b63d3-7b2c-4ede-b3fe-ff291527b397) Malware Deobfuscate/Decode Files or Information - T1140 (3ccef7ae-cb5e-48f6-8302-897105fbf55c) Attack Pattern 1
Application Layer Protocol - T1071 (355be19c-ffc9-46d5-8d50-d6a036c675b6) Attack Pattern Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern 2
Python - T1059.006 (cc3502b5-30cc-4473-ad48-42d51a6ef6d1) Attack Pattern Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 2
Encrypted Channel - T1573 (b8902400-e6c5-4ba2-95aa-2d35b442b118) Attack Pattern Symmetric Cryptography - T1573.001 (24bfaeba-cb0d-4525-b3dc-507c77ecec41) Attack Pattern 2