BlackMould
S0564 · Windows
BlackMould is a web shell based on China Chopper for servers running Microsoft IIS. First reported in December 2019, it has been used in malicious campaigns by GALLIUM against telecommunication providers.
ATT&CK S0564
Sigma rules0
YARA rules0
Live IOCs0