Mivast is a backdoor that has been used by Deep Panda. It was reportedly used in the Anthem breach. 
|Enterprise||T1547||.001||Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder||
Mivast creates the following Registry entry:
|Enterprise||T1059||.003||Command and Scripting Interpreter: Windows Command Shell||
Mivast has the capability to open a remote shell and run basic commands.
|Enterprise||T1105||Ingress Tool Transfer||
Mivast has the capability to download and execute .exe files.
|Enterprise||T1003||.002||OS Credential Dumping: Security Account Manager||
Mivast has the capability to gather NTLM password information.