SpeakUp
MITRE ATT&CK: S0374 View on attack.mitre.org
Aliases: SpeakUp
- First seen
- 2019-01-01 00:00:00
- Malware type
- trojan, backdoor
- Family
- Malware family
- Operating systems
- linux, macos
- Profile updated
- 2026-07-07 14:30:15
Targeted industries: technology-and-telecommunications energy-and-utilities
Context
SpeakUp is a Trojan backdoor that targets both Linux and OSX devices. It was first observed in January 2019.
Detection coverage
- 319 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- Cron (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Python (attack-pattern)
- Password Guessing (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- File Deletion (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Standard Encoding (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Network Connections Discovery (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Speakup (report)
- research.checkpoint.com — Speakup A New Undetected Backdoor Linux Trojan (report)
- MITRE ATT&CK — S0374 (report)