BlackMould — Malware Profile

BlackMould is a web shell based on China Chopper for servers running Microsoft IIS. First reported in December 2019, it has been used in malicious campaigns by GALLIUM against telecommunication providers.

MITRE ATT&CK techniques (6)

Attributed threat actors

Read the full analysis on IntelFusions