QUIETEXIT
MITRE ATT&CK: S1084 View on attack.mitre.org
Aliases: QUIETEXIT
- First seen
- 2021-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- network-devices
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-10 14:43:31
- Profile updated
- 2026-07-07 13:01:09
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:ru country_code:cn
Context
QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least 2021. APT29 has deployed QUIETEXIT on opaque network appliances that typically don't support antivirus or endpoint detection and response tools within a victim environment.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to QUIETEXIT (S1084). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | fff2c6217999f7bcdb75a4b991cc7ca785cdd0a539e28b0f49389578a8d72443 | 2026-07-10 | 1 |
Detection coverage
- 1 YARA rules
- 28 Sigma rules
Malware & tools used
- External Proxy (attack-pattern)
- Fallback Channels (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- APT29 (threat-actor)
Detection rules
- SEKOIA_Apt_Unc3524_Quietexit_Strings (yara-rule)
Reports & references
- Mandiant — Unc3524 Eye Spy Email (report)
- Mandiant — Unc3524 Eye Spy Email (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Quietexit (report)
- mandiant.widen.net — M Trends 2023 (report)
- MITRE ATT&CK — S1084 (report)