TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm. 
When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.
|Enterprise||T1547||.001||Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder||
TINYTYPHON installs itself under Registry Run key to establish persistence.
|Enterprise||T1083||File and Directory Discovery||
TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions.
|Enterprise||T1027||Obfuscated Files or Information||
TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file.