Pandora — Malware Profile
Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.
MITRE ATT&CK techniques (13)
- T1027.015 Compression
- T1055 Process Injection
- T1057 Process Discovery
- T1068 Exploitation for Privilege Escalation
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1205 Traffic Signaling
- T1543.003 Windows Service
- T1553.006 Code Signing Policy Modification
- T1569.002 Service Execution
- T1573.001 Symmetric Cryptography
- T1574.001 DLL