TINYTYPHON
MITRE ATT&CK: S0131 View on attack.mitre.org
Aliases: TINYTYPHON
- Malware type
- backdoor, worm
- Family
- Malware family
- Profile updated
- 2026-07-07 12:47:59
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm.
Detection coverage
- 1 YARA rules
- 61 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Automated Exfiltration (attack-pattern)
Used by threat actors
- Patchwork (threat-actor)
Detection rules
- MALPEDIA_Win_Tinytyphon_Auto (yara-rule)
Reports & references
- forcepoint.com — Monsoon Analysis Apt Campaign (report)
- forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tinytyphon (report)
- MITRE ATT&CK — S0131 (report)