LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0211: Linfo

MITRE ATT&CK S0211: Linfo Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0211MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Linfo is a Windows rootkit trojan described by ATT&CK as opening a backdoor on compromised hosts and being used by Elderwood. Its ATT&CK relationships make it relevant beyond simple malware identification: the mapped behaviors include local data collection, discovery of processes, system details, files and directories, command-shell execution, tool transfer, fallback command-and-control, scheduled transfer, and file deletion. For leaders, the practical issue is whether the organization can see and investigate a Windows host that is both hiding activity and enabling continued remote access.

Executive priority

Prioritize Linfo as a readiness test for endpoint visibility, incident response containment, and evidence quality rather than as a standalone malware signature problem. The business question is: if a Windows backdoor with rootkit characteristics performed discovery, collected local data, transferred tools, used fallback communications, scheduled transfer activity, and deleted files, would the SOC have enough host and network evidence to scope the incident and support audit or legal reporting decisions?

Technical view

For SOC, detection engineering, and IR teams, validate coverage around the related ATT&CK behaviors: T1059.003 Windows Command Shell, T1057 Process Discovery, T1082 System Information Discovery, T1083 File and Directory Discovery, T1005 Data from Local System, T1105 Ingress Tool Transfer, T1008 Fallback Channels, T1029 Scheduled Transfer, and T1070.004 File Deletion. Because ATT&CK provides no official detection text for Linfo, detections should be behavior-led and correlated across Windows endpoint activity, process execution, file activity, and outbound network communications rather than relying only on a malware name.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, especially cmd.exe activity
  • Process enumeration and system information query evidence
  • File and directory enumeration activity on local systems
  • File creation, modification, transfer, and deletion events
  • Network connection logs showing outbound command-and-control-like communications and possible fallback destinations or protocols

Detection direction

  • Build detections around chains of behavior: command shell execution followed by discovery, local file access, tool transfer, outbound communication, and cleanup.
  • Tune for administrative false positives by comparing discovery and file enumeration activity against known management, backup, software deployment, and troubleshooting workflows.
  • Validate that file deletion telemetry is retained long enough to support post-incident reconstruction, since cleanup behavior can remove local artifacts.
  • Look for repeated or alternate outbound communication patterns that may indicate fallback channels, especially when paired with suspicious endpoint behavior.
  • Test whether scheduled or interval-based transfer activity is visible in both host and network telemetry.

Mitigation priorities

  • Ensure Windows endpoint monitoring and response coverage can collect process, file, and network evidence needed for backdoor and rootkit investigations.
  • Harden and monitor use of Windows command shell where feasible, focusing on unauthorized or unusual administrative execution patterns.
  • Apply least-privilege and administrative access controls so discovery, collection, deletion, and tool-transfer behaviors have less opportunity to succeed unnoticed.
  • Strengthen egress monitoring and control to reduce the reliability of fallback command-and-control and unauthorized transfer paths.
  • Retain logs and forensic evidence long enough to investigate scheduled transfer and file deletion activity.
Additional notes and limits

The most useful way to operationalize this object is as a backdoor/rootkit behavior coverage review. The Elderwood reference is supplied by ATT&CK, but local prioritization should be based on whether Windows endpoints with sensitive data or privileged access have adequate monitoring and containment procedures.

ATT&CK provides a short description and no official detection guidance for Linfo. The object platform is Windows, while several related techniques list broader or non-Windows platforms in the supplied relationship context; this take applies the malware platform conservatively to Windows and uses the relationships only to frame likely behavior categories. No active exploitation, current campaign activity, or guaranteed detection coverage is implied.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Linfo

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
161585796446557a...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.