Mafalda
MITRE ATT&CK: S1060 View on attack.mitre.org
Aliases: Mafalda
- First seen
- 2022-10-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:23:07
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Mafalda is a flexible interactive implant that has been used by Metador. Security researchers assess the Mafalda name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s.
Detection coverage
- 725 Sigma rules
Malware & tools used
- Port Knocking (attack-pattern)
- Make and Impersonate Token (attack-pattern)
- External Remote Services (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Command Shell (attack-pattern)
- Modify Registry (attack-pattern)
- Private Keys (attack-pattern)
- Service Execution (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Local Data Staging (attack-pattern)
- Data from Local System (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- Internal Proxy (attack-pattern)
- Process Discovery (attack-pattern)
- Input Capture (attack-pattern)
- Web Protocols (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Information Discovery (attack-pattern)
Used by threat actors
- Metador (threat-actor)
Reports & references
- assets.sentinelone.com — Metador (report)
- MITRE ATT&CK — S1060 (report)