LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0248: yty

yty is a modular, plugin-based malware framework. The components of the framework are written in a variety of programming languages. [1]

EnterpriseS0248MalwareObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

yty is a Windows malware framework described by ATT&CK as modular and plugin-based. Its business significance is less about one fixed behavior and more about flexibility: a plugin framework can support discovery, collection, credential capture, persistence, command-and-control, and evasion behaviors depending on what components are deployed. For leaders, that means readiness should be measured across the intrusion lifecycle, not only by whether a single malware signature is blocked.

Executive priority

Prioritize validation of endpoint visibility, Windows persistence monitoring, and incident response playbooks for modular malware. The ATT&CK relationships show behaviors that can expose sensitive local data, user activity, credentials entered through the keyboard, screenshots, host and network context, and external bidirectional communications. Executives should ask whether SOC evidence is sufficient to reconstruct what was discovered, what was collected, how persistence was established, and whether C2 traffic used legitimate web services that may be harder to distinguish from normal business traffic.

Technical view

ATT&CK provides no official detection text for yty, so defenders should build coverage from the related techniques. On Windows, validate monitoring for Scheduled Task creation or modification, process and command execution associated with discovery, file and directory enumeration, local data access, keylogging indicators, screen capture activity, packed or obfuscated binaries, sandbox or system-check behavior, and outbound bidirectional web-service communications. Because the malware is described as modular and plugin-based, detection engineering should correlate multiple weak signals across execution, persistence, discovery, collection, credential-access, command-and-control, and defense-evasion behaviors rather than relying only on static file signatures.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows Task Scheduler events and task registration artifacts
  • File system access and directory enumeration evidence
  • Local data access patterns involving user files, configuration files, databases, or other sensitive local sources
  • User, process, system, network configuration, remote system, and local storage discovery telemetry

Detection direction

  • Start with behavioral detections mapped to the related techniques instead of a single yty indicator set, because ATT&CK does not provide official detection guidance.
  • Correlate Scheduled Task activity with nearby file writes, process launches, discovery commands, or suspicious child processes on Windows endpoints.
  • Tune discovery detections for abnormal combinations of user, process, file, directory, system, network, remote host, and storage enumeration, while accounting for legitimate administration and inventory tooling.
  • Review web egress for unusual bidirectional use of legitimate external web services, especially from endpoints that also show discovery or collection behavior.
  • Treat packing, junk code, and system-check behavior as triage accelerators rather than standalone proof of compromise, since benign and commercial software may also be packed or environment-aware.

Mitigation priorities

  • Maintain strong endpoint prevention and monitoring on Windows systems, with emphasis on execution control, suspicious task scheduling, and malware behavior analytics.
  • Harden and audit Windows Task Scheduler usage so unauthorized persistence is easier to prevent or investigate.
  • Limit unnecessary local access to sensitive files and reduce credential exposure on endpoints where practical.
  • Apply least privilege so malware running in a user context has reduced ability to collect broader system, user, and network information.
  • Control and monitor outbound web access, including legitimate web services that could be abused for bidirectional command-and-control.
Additional notes and limits

The supplied ATT&CK object identifies yty as a modular, plugin-based malware framework and links it to multiple techniques, including local data collection, discovery, scheduled task persistence/execution, keylogging, screen capture, obfuscation, system checks, and bidirectional web-service C2. This supports a defense strategy centered on behavior correlation and forensic reconstruction. The object itself lists Windows as the platform; related techniques may include additional platforms, but platform-specific coverage claims for yty should remain Windows-focused unless local intelligence supports more.

ATT&CK does not provide official detection guidance, aliases, labels, or explicit tactics for the malware object. The source material provided is limited to the ATT&CK fields, one external report reference, and technique relationships. This summary does not establish current activity, attribution, prevalence, customer exposure, or guaranteed detection coverage. Local telemetry, malware samples, and environment-specific baselines are required to operationalize detections safely.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

yty

yty is a modular, plugin-based malware framework. The components of the framework are written in a variety of programming languages. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1680Local Storage Discovery

yty gathers the the serial number of the main disk volume.[1]

EnterpriseT1083File and Directory Discovery

yty gathers information on victim’s drives and has a plugin for document listing.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

yty establishes persistence by creating a scheduled task with the command SchTasks /Create /SC DAILY /TN BigData /TR “ + path_file + “/ST 09:30“.[1]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

yty communicates to the C2 server by retrieving a Google Doc.[1]

EnterpriseT1027.016Junk Code InsertionSub-technique

yty contains junk code in its binary, likely to confuse malware analysts.[1]

EnterpriseT1018Remote System Discovery

yty uses the net view command for discovery.[1]

EnterpriseT1005Data from Local System

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.[1]

EnterpriseT1497.001System ChecksSub-technique

yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware. [1]

EnterpriseT1057Process Discovery

yty gets an output of running processes using the tasklist command.[1]

EnterpriseT1033System Owner/User Discovery

yty collects the victim’s username.[1]

EnterpriseT1082System Information Discovery

yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command systeminfo.[1]

EnterpriseT1056.001KeyloggingSub-technique

yty uses a keylogger plugin to gather keystrokes.[1]

EnterpriseT1113Screen Capture

yty collects screenshots of the victim machine.[1]

EnterpriseT1027.002Software PackingSub-technique

yty packs a plugin with UPX.[1]

EnterpriseT1016System Network Configuration Discovery

yty runs ipconfig /all and collects the domain name.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
f59d8d98d4d07391...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundlef59d8d98d4d0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  2. [2]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  3. [3]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  4. [4]
    mitre-attackS0248
    Open source URL
  5. [5]
    mitre-attackS0248
    Open source URL
  6. [6]
    mitre-attackS0248
    Open source URL
  7. [7]
    yty

    (Citation: ASERT Donot March 2018)

  8. [8]
    yty

    (Citation: ASERT Donot March 2018)

  9. [9]
    yty

    (Citation: ASERT Donot March 2018)

  10. [10]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  11. [11]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  12. [12]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  13. [13]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  14. [14]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  15. [15]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  16. [16]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  17. [17]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  18. [18]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  19. [19]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  20. [20]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  21. [21]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  22. [22]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  23. [23]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  24. [24]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  25. [25]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  26. [26]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  27. [27]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  28. [28]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  29. [29]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  30. [30]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  31. [31]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  32. [32]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  33. [33]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  34. [34]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  35. [35]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  36. [36]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  37. [37]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
  38. [38]
    ASERT Donot March 2018

    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.