Pandora

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Pandora](https://attack.mitre.org/software/S0664) is a multistage kernel rootkit with backdoor functionality that has been in use by [Threat Group-3390](https://attack.mitre.org/groups/G0027) since at least 2020.(Citation: Trend Micro Iron Tiger April 2021)

Associated Techniques (13)
ID ATT&CK Tactics
T1027.015 Compression -
T1055 Process Injection -
T1057 Process Discovery -
T1068 Exploitation for Privilege Escalation -
T1071.001 Web Protocols -
T1105 Ingress Tool Transfer -
T1112 Modify Registry -
T1205 Traffic Signaling -
T1543.003 Windows Service -
T1553.006 Code Signing Policy Modification -
T1569.002 Service Execution -
T1573.001 Symmetric Cryptography -
T1574.001 DLL -
Metadata
ID: 466
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00