ELMER

MITRE ATT&CK: S0064 View on attack.mitre.org

Aliases: Elmost, ELMER

First seen
2014-02-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:35:52

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:tw country_code:jp

Context

ELMER is a non-persistent, proxy-aware HTTP backdoor written in Delphi that has been used by APT16.

Detection coverage

  • 59 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — G0023 (report)
  • Mandiant — The Eps Awakens Part Two (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Elmer (report)
  • cybergeeks.tech — A Detailed Analysis Of Elmer Backdoor Used By Apt16 (report)
  • MITRE ATT&CK — S0064 (report)
  • Broadcom/Symantec — 2015 122210 5724 99 (report)
  • web.archive.org — The Eps Awakens Part Two (report)

External references