QUIETEXIT — Malware Profile
QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least 2021. APT29 has deployed QUIETEXIT on opaque network appliances that typically don't support antivirus or endpoint detection and response tools within a victim environment.
MITRE ATT&CK techniques (5)
- T1008 Fallback Channels
- T1036.005 Match Legitimate Resource Name or Location
- T1071 Application Layer Protocol
- T1090.002 External Proxy
- T1095 Non-Application Layer Protocol