Wingbird
MITRE ATT&CK: S0176 View on attack.mitre.org
Aliases: Wingbird
- First seen
- 2016-05-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:49:48
Targeted industries: government-and-public-sector
Targeted regions: country_code:de
Context
Wingbird is a backdoor that appears to be a version of commercial software FinFisher. It is reportedly used to attack individual computers instead of networks. It was used by NEODYMIUM in a May 2016 campaign.
Detection coverage
- 249 Sigma rules
Malware & tools used
- DLL (attack-pattern)
- File Deletion (attack-pattern)
- Service Execution (attack-pattern)
- Windows Service (attack-pattern)
- Security Software Discovery (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Process Injection (attack-pattern)
- System Information Discovery (attack-pattern)
- LSASS Driver (attack-pattern)
Used by threat actors
- NEODYMIUM (threat-actor)
Reports & references
- Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
- Microsoft — Microsoft Security Intelligence Report Volume 21 English (report)
- MITRE ATT&CK — S0176 (report)
- Microsoft — Malware Encyclopedia Description (report)