RDFSNIFFER

MITRE ATT&CK: S0416 View on attack.mitre.org

Aliases: RDFSNIFFER

Malware type
spyware, trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:50:13

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

RDFSNIFFER is a module loaded by BOOSTWRITE which allows an attacker to monitor and tamper with legitimate connections made via an application designed to provide visibility and system management capabilities to remote IT techs.

Detection coverage

  • 24 Sigma rules

Malware & tools used

  • Credential API Hooking (attack-pattern)
  • File Deletion (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Reports & references

  • Mandiant — Mahalo Fin7 Responding To New Tools And Techniques (report)
  • MITRE ATT&CK — S0416 (report)

External references