RIFLESPINE is a cross-platform backdoor used by UNC3886 that leverages Google Drive for command-and-control and file transfer. It retrieves encrypted instruction files from Google Drive, executes commands, and uploads encrypted results back to Google Drive. Reported supported functionality includes arbitrary command execution via /bin/sh, file download (get), file upload (put), and changing its beacon interval (settime). On first installation it collects system information and begins communicating with Google Drive.
The malware uses the CryptoPP library to implement AES encryption for data transmitted between victim and operator. Observed tasking involved the actor placing an encrypted instruction file on Google Drive; RIFLESPINE searched for a filename pattern containing the victim MAC address, downloaded the tasking file to /tmp using the open-source gdrive CLI, decrypted it, executed the instructions, encrypted command output, staged the output in a temporary file, and uploaded the results back to Google Drive. Observed artifacts include temporary files under /tmp such as /tmp/syslog<random_number>.rs, use of gdrive list/download/upload commands, and filename matching containing "2@<mac_address>". One report states decryption used AES-CBC with keys/IV derived from libcrypt.so.2 and libev.so.5.
UNC3886 deployed RIFLESPINE on compromised Linux virtual machines in VMware environments. Because the malware lacked its own persistence mechanism, the actor created a systemd service file to execute it. Mandiant observed RIFLESPINE only on a small number of compromised virtual machines and assessed the actor likely abandoned use of it, along with MOPSLED.LINUX, because the predictable GitHub/Google Drive communications from VM servers were suspicious and the malware lacked rootkit-like stealth capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...either through the collection of vpxuser credentials or by exploiting CVE-2023-20867 in conjunction with VMware Guest Operations abuse to facilitate malicious file transfer and execution..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"RIFLESPINE is a cross-platform backdoor that leverages Google Drive to transfer files and execute commands."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"...deploying malware, including MOPSLED and RIFLESPINE, that leverages trusted third parties like GitHub and Google Drive as C2 channels while relying on the rootkits for persistence."
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
Clambling can use Dropbox to download malicious payloads, send commands, and receive information. ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands.
ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. Crutch can use Dropbox to receive commands and upload stolen data. RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... RIFLESPINE ... (v1.0) ...
RIFLESPINE (v1.0)
Malware that uploads command execution results to cloud storage.
Backdoor that uses Google Drive for encrypted command retrieval and for uploading execution results.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.