GRIFFON

GRIFFON is a JavaScript backdoor used by FIN7. [1]

ID: S0417
Type: MALWARE
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1069 Permission Groups Discovery

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.[1]

Enterprise T1086 PowerShell

GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet.[1]

Enterprise T1060 Registry Run Keys / Startup Folder

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.[1]

Enterprise T1053 Scheduled Task

GRIFFON has used sctasks for persistence.[1]

Enterprise T1113 Screen Capture

GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system.[1]

Enterprise T1082 System Information Discovery

GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .[1]

Enterprise T1124 System Time Discovery

GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system. [1]

Groups That Use This Software

ID Name References
G0046 FIN7 [1]

References