QUIETEXIT

MITRE ATT&CK: S1084 View on attack.mitre.org

Aliases: QUIETEXIT

First seen
2021-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
network-devices
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-10 14:43:31
Profile updated
2026-07-07 13:01:09

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least 2021. APT29 has deployed QUIETEXIT on opaque network appliances that typically don't support antivirus or endpoint detection and response tools within a victim environment.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to QUIETEXIT (S1084). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample fff2c6217999f7bcdb75a4b991cc7ca785cdd0a539e28b0f49389578a8d72443 2026-07-10 1

Detection coverage

  • 1 YARA rules
  • 28 Sigma rules

Malware & tools used

  • External Proxy (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Unc3524_Quietexit_Strings (yara-rule)

Reports & references

  • Mandiant — Unc3524 Eye Spy Email (report)
  • Mandiant — Unc3524 Eye Spy Email (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Quietexit (report)
  • mandiant.widen.net — M Trends 2023 (report)
  • MITRE ATT&CK — S1084 (report)

External references