ZIPLINE — Malware Profile
ZIPLINE is a passive backdoor that was used during Cutting Edge on compromised Secure Connect VPNs for reverse shell and proxy functionality.
MITRE ATT&CK techniques (9)
- T1057 Process Discovery
- T1059.004 Unix Shell
- T1083 File and Directory Discovery
- T1090 Proxy
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1205 Traffic Signaling
- T1573.001 Symmetric Cryptography
- T1685 Disable or Modify Tools
Attributed threat actors
- UNC5221 machine-inferred link