If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1554 - Compromise Host Software Binar.

site address: attack.mitre.org/techniques/T1554 redirected to: attack.mitre.org/techniques/T1554

site title: Compromise Host Software Binary, Technique T1554 - Enterprise MITRE ATT&CK®

Our opinion (on Wednesday 12 August 2026 17:53:47 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

compromise, host, software, binary, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
the (48), and (25), retrieved (24), for (17), 2024 (16), may (15), secure (15), binaries (15), file (15), legitimate (13), all (12), #software (12), binary (12), ivanti (11), connect (11), att (10), malicious (9), persistence (9), with (9), can (9), techniques (8), 2021 (8), february (8), host (8), modify (8), 2026 (7), enterprise (7), zero (7), day (7), january (7), vpn (7), application (7), execution (7), has (7), version (7), adversary (7), mobile (6), 2020 (6), malware (6), 2023 (6), march (6), thiefquest (6), new (6), exploitation (6), pulse (6), systems (6), modification (6), files (6), system (6), trojanized (6), are (5), ics (5), none (5), code (5), into (5), backdoor (5), linux (5), cutting (5), edge (5), vpns (5), that (5), mitre (4), components (4), defenses (4), threat (4), suspected (4), july (4), after (4), 2025 (4), april (4), december (4), ebury (4), openssh (4), actors (4), industroyer (4), unc3886 (4), applications (4), signed (4), executed (4), modified (4), bin (4), compromise (4), itself (4), compromised (4), through (4), during (4), cgi (4), ssh (4), client (4), user (4), also (4), use (3), reset (3), resources (3), cti (3), data (3), detection (3), mitigations (3), sub (3), mac (3), xcsset (3), october (3), used (3), chinese (3), part (3), redpenguin (3), june (3), lin (3), targeted (3), mini (3), shai (3), hulud (3), kobalos (3), glassworm (3), léveillé (3), apt (3), attempts (3), september (3), detects (3), correlates (3), unexpected (3), behavior (3), monitors (3), library (3), process (3), modifications (3), normal (3), description (3), component (3), uses (3), credentials (3), web (3), command (3), embed (3), replaced (3), executable (3), patching (3), attack (3), modifying (3), hooks (3), windows (3), cav (3), iat (3), bfg (3), agonizer (3), point (3), clients (3), corporation (2), domains (2), reference (2), campaigns (2), groups (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), team (2), august (2), two (2), marvi (2), fortinet (2), espionage (2), daniel (2), goes (2), infrastructure (2), investigating (2), 2022 (2), chechik (2), perez (2), your (2), updates (2), leverage (2), authentication (2), bypass (2), modules (2), services (2), esxi (2), tampered (2), subsequent (2), service (2), unsigned (2), monitoring (2), usr (2), other (2), events (2), executables (2), analytic (2), name (2), browser (2), replace (2), order (2), download (2), additional (2), arbitrary (2), wirefire (2), warpwire (2), functionality (2), when (2), hidden (2), slowpulse (2), enable (2), including (2), upgrades (2), commands (2), dsupgrade (2), phasejam (2), attempt (2), littlelamb (2), wooltea (2), lightwire (2), maliciously (2), altered (2), create (2), kessel (2), notepad (2), package (2), home (2), framesting (2), add (2), bushwalk (2), bonadan (2), boldmove (2), unhooking (2), remove (2), mode (2), security (2), solutions (2), apt5 (2), 2016 (2), ukraine (2), electric (2), power (2), t1554 (2), yum (2), versionlock (2), entry (2), example (2), adversaries (2), establish (2), persistent (2), access (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, filters, response, research, inserts, xcode, projects, performs, uxss, planting, safari, leverages, exploits, custom, actor, operation, thomas, reed, not, ransomware, patrick, wardle, osx, evilquest, uncovered, insidious, capabilities, juniper, networks, cybersecurity, incident, john, wolfram, josh, murchie, matt, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, flashpoint, worm, era, leveille, sanmillan, wild, appears, tricksy, hpcs, gal, hachamov, fresh, tricks, marc, etienne, alive, but, unseen, 2014, depth, analysis, 2019, meltzer, active, vulnerabilities, mclellan, targets, dumont, porcher, 2018, dark, side, forsshe, landscape, backdoors, scott, henderson, cristiana, kittner, sarah, hawley, mark, lechtik, google, cloud, exploiting, fortios, vulnerability, cve, 42475, tom, fakterman, frank, assaf, dahan, november, agonizing, serpens, aka, agrius, targeting, israeli, higher, education, tech, sectors, checking, compromising, devices, check, anton, cherepanov, 2017, win32, industrial, controls, vladislav, hrčka, fontonlake, banking, trojan, how, financially, motivated, became, punsaen, boonyakarn, shawn, chew, logeswaran, nadarajan, mathew, potaczek, jakub, jozwiak, alex, cloaked, covert, uncovering, operations, references, unauthorized, within, module, load, an0952, paths, improperly, tracks, gatekeeper, notarization, tied, an0951, privileged, directories, integrity, fim, executions, restarts, an0950, particularly, write, anomalously, checks, outside, patch, cycles, an0949, detect, det0336, strategy, ensure, correct, developers, signing, m1045, mitigation, continuously, capture, monitor, traffic, s0658, visits, s1115, s1116, firmware, tacacs, daemon, containing, credential, logging, tac_plus, g1048, searches, folder, looking, each, prepends, copy, beginning, first, creates, copies, original, target, then, executes, maintain, appearance, users, s0595, applied, environments, s1104, peformed, local, memory, snmpd, mgd, junos, daemons, c0056, inserting, shell, block, overwriting, execute, specific, parameters, provided, remotedebug, restauth, getcomponent, s9014, established, include, coding, agents, configuration, setting, act, tasks, triggers, s9043, append, archive, inside, factory, partition, persist, post, tmp, tmpmnt, samba_upgrade, tar, s1121, imbed, compcheckresult, s1119, steal, s0641, s0487, mechanism, s0604, hardware, wallet, s9010, python, located, venv3, lib, python3, site, packages, py3, egg, api, category, s1120, modifies, curl, keyutils, s0377, appliances, c0029, querymanifest, s1118, s0486, contains, watchdog, like, feature, particular, detected, backed, allow, likely, s1184, dll, inline, often, implement, s1136, scripts, install, atrium, webshell, g1023, layer, sandworm, c0025, procedure, examples, live, permalink, last, created, crowdstrike, falcon, overwatch, jamie, williams, panw, unit, liran, ravich, cardinalops, contributors, macos, platforms, tactic, impair, preventing, from, updating, via, manager, list, existing, hooking, prior, patched, before, resuming, flow, though, otherwise, infect, support, since, these, routinely, this, such, persistently, collect, logins, provide, wide, range, programs, libraries, common, ftp, email, browsers, many, server, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,


Text of the page (random words):
compromise host software binary technique t1554 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise compromise host software binary compromise host software binary adversaries may modify host software binaries to establish persistent access to systems software binaries executables provide a wide range of system commands or services programs and libraries common software binaries are ssh clients ftp clients email clients web browsers and many other user or server applications adversaries may establish persistence though modifications to host software binaries for example an adversary may replace or otherwise infect a legitimate application binary or support files with a backdoor since these binaries may be routinely executed by applications or the user the adversary can leverage this for persistent access to the host an adversary may also modify a software binary such as an ssh client in order to persistently collect credentials during logins i e modify authentication process 1 an adversary may also modify an existing binary by patching in malicious functionality e g iat hooking entry point patching 2 prior to the binary s legitimate execution for example an adversary may modify the entry point of a binary to point to malicious code patched in by the adversary before resuming normal execution flow 3 after modifying a binary an adversary may attempt to impair defenses by preventing it from updating e g via the yum versionlock command or versionlock list file in linux systems that use the yum package manager 1 id t1554 sub techniques no sub techniques ⓘ tactic persistence ⓘ platforms esxi linux windows macos contributors crowdstrike falcon overwatch jamie williams u ω u panw unit 42 liran ravich cardinalops version 2 2 created 11 february 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0025 2016 ukraine electric power attack during the 2016 ukraine electric power attack sandworm team used a trojanized version of windows notepad to add a layer of persistence for industroyer 4 g1023 apt5 apt5 has modified legitimate binaries and scripts for pulse secure vpns including the legitimate dsupgrade pm file to install the atrium webshell for persistence 5 6 s1136 bfg agonizer bfg agonizer uses dll unhooking to remove user mode inline hooks that security solutions often implement bfg agonizer also uses iat unhooking to remove user mode iat hooks that security solutions also use 7 s1184 boldmove boldmove contains a watchdog like feature that monitors a particular file for modification if modification is detected the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades 8 s0486 bonadan bonadan has maliciously altered the openssh binary on targeted systems to create a backdoor 9 s1118 bushwalk bushwalk can embed into the legitimate querymanifest cgi file on compromised ivanti connect secure vpns 10 11 c0029 cutting edge during cutting edge threat actors trojanized legitimate files in ivanti connect secure appliances with malicious code 12 13 10 s0377 ebury ebury modifies the keyutils library to add malicious behavior to the openssh client and the curl library 14 15 s1120 framesting framesting can embed itself in the cav python package of an ivanti connect secure vpn located in home venv3 lib python3 6 site packages cav 0 1 py3 6 egg cav api resources category py 10 s9010 glassworm glassworm can modify hardware wallet applications 16 s0604 industroyer industroyer has used a trojanized version of the windows notepad application for an additional backdoor persistence mechanism 4 s0487 kessel kessel has maliciously altered the openssh binary on targeted systems to create a backdoor 9 s0641 kobalos kobalos replaced the ssh client with a trojanized ssh client to steal credentials on compromised systems 17 s1119 lightwire lightwire can imbed itself into the legitimate compcheckresult cgi component of ivanti connect secure vpns to enable command execution 12 10 s1121 littlelamb wooltea littlelamb wooltea can append malicious components to the tmp tmpmnt bin samba_upgrade tar archive inside the factory reset partition in attempt to persist post reset 11 s9043 mini shai hulud mini shai hulud has established persistence through modifying software binaries to include ai coding agents configuration or setting files that act as hooks tasks or execution triggers 18 s9014 phasejam phasejam has modified legitimate components to enable persistence and execution including inserting a web shell into getcomponent cgi and restauth cgi modifying dsupgrade pm to block system upgrades and overwriting remotedebug to execute arbitrary commands when specific parameters are provided 19 c0056 redpenguin during redpenguin unc3886 peformed a local memory patching attack to modify the snmpd and mgd junos os daemons 20 s1104 slowpulse slowpulse is applied in compromised environments through modifications to legitimate pulse secure files 6 s0595 thiefquest thiefquest searches through the users folder looking for executable files for each executable thiefquest prepends a copy of itself to the beginning of the file when the file is executed the thiefquest code is executed first thiefquest creates a hidden file copies the original target executable to the file then executes the new hidden file to maintain the appearance of normal behavior 21 22 g1048 unc3886 unc3886 has trojanized fortinet firmware and replaced the legitimate usr bin tac_plus tacacs daemon for linux with a malicious version containing credential logging functionality 1 23 s1116 warpwire warpwire can embed itself into a legitimate file on compromised ivanti connect secure vpns 12 s1115 wirefire wirefire can modify the visits py component of ivanti connect secure vpns for file download and arbitrary command execution 12 13 s0658 xcsset xcsset uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials monitor web traffic and download additional modules 24 mitigations id mitigation description m1045 code signing ensure all application component binaries are signed by the correct application developers detection strategy id name analytic id analytic description det0336 detect compromise of host software binaries an0949 monitors for unexpected modifications of system or application binaries particularly signed executables correlates file write events with subsequent unsigned or anomalously signed process execution and checks for tampered binaries outside normal patch cycles an0950 detects modification of system or application binaries by monitoring usr bin bin and other privileged directories correlates file integrity monitoring fim events with unexpected process executions or service restarts an0951 monitors binary modification in applications and system library paths detects unsigned or improperly signed binaries executed after modification tracks gatekeeper or notarization bypass attempts tied to modified binaries an0952 detects unauthorized modification of host binaries modules or services within esxi correlates tampered files with subsequent unexpected service behavior or malicious module load attempts references punsaen boonyakarn shawn chew logeswaran nadarajan mathew potaczek jakub jozwiak and alex marvi 2024 june 18 cloaked and covert uncovering unc3886 espionage operations retrieved september 24 2024 or chechik 2022 october 31 banking trojan techniques how financially motivated malware became infrastructure retrieved september 27 2023 vladislav hrčka 2021 january 1 fontonlake retrieved september 27 2023 anton cherepanov 2017 june 12 win32 industroyer a new threat for industrial controls systems retrieved december 18 2020 perez d et al 2021 april 20 check your pulse suspected apt actors leverage authentication bypass techniques and pulse secure zero day retrieved february 5 2024 perez d et al 2021 may 27 re checking your pulse updates on chinese apt actors compromising pulse secure vpn devices retrieved february 5 2024 or chechik tom fakterman daniel frank assaf dahan 2023 november 6 agonizing serpens aka agrius targeting the israeli higher education and tech sectors retrieved may 22 2024 scott henderson cristiana kittner sarah hawley mark lechtik google cloud 2023 january 19 suspected chinese threat actors exploiting fortios vulnerability cve 2022 42475 retrieved december 31 2024 dumont r m léveillé m porcher h 2018 december 1 the dark side of the forsshe a landscape of openssh backdoors retrieved july 16 2020 lin m et al 2024 january 31 cutting edge part 2 investigating ivanti connect secure vpn zero day exploitation retrieved february 27 2024 lin m et al 2024 february 27 cutting edge part 3 investigating ivanti connect secure vpn exploitation and persistence attempts retrieved march 1 2024 mclellan t et al 2024 january 12 cutting edge suspected apt targets ivanti connect secure vpn in new zero day exploitation retrieved february 27 2024 meltzer m et al 2024 january 10 active exploitation of two zero day vulnerabilities in ivanti connect secure vpn retrieved february 27 2024 m léveillé m 2014 february 21 an in depth analysis of linux ebury retrieved april 19 2019 marc etienne m léveillé 2024 may 1 ebury is alive but unseen retrieved may 21 2024 gal hachamov 2025 december 29 glassworm goes mac fresh infrastructure new tricks retrieved april 10 2026 m leveille m sanmillan i 2021 january a wild kobalos appears tricksy linux malware goes after hpcs retrieved august 24 2021 flashpoint 2026 may 28 the mini shai hulud worm and the new era of ci cd exploitation retrieved july 16 2026 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 juniper networks cybersecurity r d 2025 march 11 the redpenguin malware incident retrieved june 24 2025 patrick wardle 2020 july 3 osx evilquest uncovered part ii insidious capabilities retrieved march 21 2021 thomas reed 2020 july 7 mac thiefquest malware may not be ransomware after all retrieved march 22 2021 marvi a et al 2023 march 16 fortinet zero day and custom malware used by suspected chinese actor in espionage operation retrieved march 22 2023 mac threat response mobile research team 2020 august 13 the xcsset malware inserts malicious code into xcode projects performs uxss backdoor planting in safari and leverages two zero day exploits retrieved october 5 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 71 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-71


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1554
X-GitHub-Request-Id 7D1C:3D3A:329E88:32F6F8:6A7CB32B
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Wed, 12 Aug 2026 17:53:47 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290042-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786557227.335443,VS0,VE105
Vary Accept-Encoding
X-Fastly-Request-ID 721cb03f3fae189c2965e99183d68e6b0bd58f75
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1554/
access-control-allow-origin *
expires Wed, 12 Aug 2026 18:03:47 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 99A2:6B8F9:3F1BF:42B14:6A7CB32A
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Wed, 12 Aug 2026 17:53:47 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630039-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786557227.469874,VS0,VE91
vary Accept-Encoding
x-fastly-request-id ea69853b86eec9a630657446db8b8b7727eb578b
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-14354
expires Wed, 12 Aug 2026 18:03:47 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 779A:2A6C37:3E92E:42282:6A7CB32B
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Wed, 12 Aug 2026 17:53:47 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630039-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786557228.569179,VS0,VE105
vary Accept-Encoding
x-fastly-request-id 3f504c6e38e2467d8f0e22e89f92d95bcd9dfb03
content-length 13419

Meta Tags

title="Compromise Host Software Binary, Technique T1554 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size13419
load time (s)0.830408
redirect count2
speed download16167
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"