T9000
MITRE ATT&CK: S0098 View on attack.mitre.org
Aliases: T9000
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:36:33
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us
Context
T9000 is a backdoor that is a newer variant of the T5000 malware family, also known as Plat1. Its primary function is to gather information about the victim. It has been used in multiple targeted attacks against U.S.-based organizations.
Detection coverage
- 182 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- AppInit DLLs (attack-pattern)
- System Information Discovery (attack-pattern)
- DLL (attack-pattern)
- Security Software Discovery (attack-pattern)
- Audio Capture (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Screen Capture (attack-pattern)
- Video Capture (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
Reports & references
- Mandiant — Spear Phishing The News Cycle Apt Actors Leverage Interest In The Disappearance Of Malaysian Flight Mh 370 (report)
- researchcenter.paloaltonetworks.com — T9000 Advanced Modular Backdoor Uses Complex Anti Analysis Techniques (report)
- MITRE ATT&CK — S0098 (report)