WINDSHIELD — Malware Profile
WINDSHIELD is a signature backdoor used by APT32.
MITRE ATT&CK techniques (5)
- T1012 Query Registry
- T1033 System Owner/User Discovery
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1095 Non-Application Layer Protocol