BLACKCOFFEE — Malware Profile
BLACKCOFFEE is malware that has been used by several Chinese groups since at least 2013.
MITRE ATT&CK techniques (7)
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1083 File and Directory Discovery
- T1102.001 Dead Drop Resolver
- T1102.002 Bidirectional Communication
- T1104 Multi-Stage Channels