BlackMould

MITRE ATT&CK: S0564 View on attack.mitre.org

Aliases: BlackMould

First seen
2019-12-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:57:49

Targeted industries: technology-and-telecommunications

Context

BlackMould is a web shell based on China Chopper for servers running Microsoft IIS. First reported in December 2019, it has been used in malicious campaigns by GALLIUM against telecommunication providers.

Detection coverage

  • 162 Sigma rules

Malware & tools used

  • Local Storage Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Reports & references

  • Microsoft — Gallium Targeting Global Telecom (report)
  • MITRE ATT&CK — S0564 (report)

External references