Milan
MITRE
Malware Type:
Other
Other
First seen:
Unknown
Unknown
Last seen:
Unknown
Unknown
Details:
[Milan](https://attack.mitre.org/software/S1015) is a backdoor implant based on [DanBot](https://attack.mitre.org/software/S1014) that was written in Visual C++ and .NET. [Milan](https://attack.mitre.org/software/S1015) has been used by [HEXANE](https://attack.mitre.org/groups/G1001) since at least June 2020.(Citation: ClearSky Siamesekitten August 2021)(Citation: Kaspersky Lyceum October 2021)
Associated Techniques (20)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1005 | Data from Local System | - |
| T1012 | Query Registry | - |
| T1016 | System Network Configuration Discovery | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1033 | System Owner/User Discovery | - |
| T1036 | Masquerading | - |
| T1036.007 | Double File Extension | - |
| T1053.005 | Scheduled Task | - |
| T1059.003 | Windows Command Shell | - |
| T1070.004 | File Deletion | - |
| T1071.001 | Web Protocols | - |
| T1071.004 | DNS | - |
| T1074.001 | Local Data Staging | - |
| T1082 | System Information Discovery | - |
| T1087.001 | Local Account | - |
Aliases (105)
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
James
Used by Actors (1)
Metadata
| ID: | 489 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |