{
  "type": "malware",
  "spec_version": "2.1",
  "id": "malware--91000a8a-58cc-4aba-9ad0-993ad6302b86",
  "created": "2017-05-31T21:33:21.437Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/software/S0142",
      "external_id": "S0142"
    },
    {
      "source_name": "StreamEx",
      "description": "(Citation: Cylance Shell Crew Feb 2017)"
    },
    {
      "source_name": "Cylance Shell Crew Feb 2017",
      "description": "Cylance SPEAR Team. (2017, February 9). Shell Crew Variants Continue to Fly Under Big AV’s Radar. Retrieved February 15, 2017.",
      "url": "https://www.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "modified": "2025-04-25T14:44:02.994Z",
  "name": "StreamEx",
  "description": "[StreamEx](https://attack.mitre.org/software/S0142) is a malware family that has been used by [Deep Panda](https://attack.mitre.org/groups/G0009) since at least 2015. In 2016, it was distributed via legitimate compromised Korean websites. (Citation: Cylance Shell Crew Feb 2017)",
  "is_family": true,
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_platforms": [
    "Windows"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_domains": [
    "enterprise-attack"
  ],
  "x_mitre_version": "1.1",
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_aliases": [
    "StreamEx"
  ]
}