Wingbird

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Wingbird](https://attack.mitre.org/software/S0176) is a backdoor that appears to be a version of commercial software [FinFisher](https://attack.mitre.org/software/S0182). It is reportedly used to attack individual computers instead of networks. It was used by [NEODYMIUM](https://attack.mitre.org/groups/G0055) in a May 2016 campaign. (Citation: Microsoft SIR Vol 21) (Citation: Microsoft NEODYMIUM Dec 2016)

Associated Techniques (9)
ID ATT&CK Tactics
T1055 Process Injection -
T1068 Exploitation for Privilege Escalation -
T1070.004 File Deletion -
T1082 System Information Discovery -
T1518.001 Security Software Discovery -
T1543.003 Windows Service -
T1547.008 LSASS Driver -
T1569.002 Service Execution -
T1574.001 DLL -
Used by Actors (1)
Metadata
ID: 478
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00