RDFSNIFFER
MITRE ATT&CK: S0416 View on attack.mitre.org
Aliases: RDFSNIFFER
- Malware type
- spyware, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:50:13
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
RDFSNIFFER is a module loaded by BOOSTWRITE which allows an attacker to monitor and tamper with legitimate connections made via an application designed to provide visibility and system management capabilities to remote IT techs.
Detection coverage
- 24 Sigma rules
Malware & tools used
- Credential API Hooking (attack-pattern)
- File Deletion (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
Reports & references
- Mandiant — Mahalo Fin7 Responding To New Tools And Techniques (report)
- MITRE ATT&CK — S0416 (report)