MOPSLED — Malware Profile
MOPSLED is a shellcode-based modular backdoor that has been used by China-nexus cyber espionage actors including UNC3886 and APT41.
MITRE ATT&CK techniques (6)
- T1027.013 Encrypted/Encoded File
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1102 Web Service
- T1102.001 Dead Drop Resolver
- T1140 Deobfuscate/Decode Files or Information