metaMain

MITRE ATT&CK: S1059 View on attack.mitre.org

Aliases: metaMain

First seen
2022-09-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:23:05

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Context

metaMain is a backdoor used by Metador to maintain long-term access to compromised machines; it has also been used to decrypt Mafalda into memory.

Detection coverage

  • 470 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Process Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Modify Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Input Capture (attack-pattern)
  • Native API (attack-pattern)
  • Screen Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Data from Local System (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Internal Proxy (attack-pattern)
  • DLL (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File Deletion (attack-pattern)
  • Keylogging (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Timestomp (attack-pattern)

Used by threat actors

Reports & references

  • assets.sentinelone.com — Metador (report)
  • MITRE ATT&CK — S1059 (report)
  • docs.google.com — Edit (report)

External references