CASTLETAP

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[CASTLETAP](https://attack.mitre.org/software/S1224) is an ICMP port knocking backdoor that has been installed on compromised FortiGate firewalls by [UNC3886](https://attack.mitre.org/groups/G1048).(Citation: Mandiant Fortinet Zero Day)

Associated Techniques (8)
ID ATT&CK Tactics
T1005 Data from Local System -
T1040 Network Sniffing -
T1059.004 Unix Shell -
T1105 Ingress Tool Transfer -
T1140 Deobfuscate/Decode Files or Information -
T1205.002 Socket Filters -
T1573.001 Symmetric Cryptography -
T1573.002 Asymmetric Cryptography -
Used by Actors (1)
Metadata
ID: 64
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00