BlackMould — Malware Profile
BlackMould is a web shell based on China Chopper for servers running Microsoft IIS. First reported in December 2019, it has been used in malicious campaigns by GALLIUM against telecommunication providers.
MITRE ATT&CK techniques (6)
- T1005 Data from Local System
- T1059.003 Windows Command Shell
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1680 Local Storage Discovery