TINYTYPHON

MITRE ATT&CK: S0131 View on attack.mitre.org

Aliases: TINYTYPHON

Malware type
backdoor, worm
Family
Malware family
Profile updated
2026-07-07 12:47:59

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign. The majority of its code was reportedly taken from the MyDoom worm.

Detection coverage

  • 1 YARA rules
  • 61 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Automated Exfiltration (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Tinytyphon_Auto (yara-rule)

Reports & references

  • forcepoint.com — Monsoon Analysis Apt Campaign (report)
  • forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tinytyphon (report)
  • MITRE ATT&CK — S0131 (report)

External references