TEXTMATE

MITRE
Tipo Malware:
Other
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[TEXTMATE](https://attack.mitre.org/software/S0146) is a second-stage PowerShell backdoor that is memory-resident. It was observed being used along with [POWERSOURCE](https://attack.mitre.org/software/S0145) in February 2017. (Citation: FireEye FIN7 March 2017)

Tecniche Associate (2)
ID ATT&CK Tattiche
T1059.003 Windows Command Shell -
T1071.004 DNS -
Alias (105)
DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger DNSMessenger
Usato da Attori (1)
Metadata
ID: 218
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00