S1060: Mafalda
Security context for executives and security teams
S1060: Mafalda describes [Mafalda](https://attack.mitre.org/software/S1060) is a flexible interactive implant that has been used by [Metador](https://attack.mitre.org/groups/G1013). Security researchers assess the [Mafalda](https://attack.mitre.org/software/S1060) name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s. (Citation: SentinelLabs Metador Sept 2022)
Executive priority
S1060: Mafalda is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S1060: Mafalda by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S1060: Mafalda appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Mafalda
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1205.001 | Port KnockingSub-technique | |
| Enterprise | T1134.003 | Make and Impersonate TokenSub-technique | Mafalda can create a token for a different user.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1133 | External Remote Services | Mafalda can establish an SSH connection from a compromised host to a server.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | |
| Enterprise | T1132.001 | Standard EncodingSub-technique | Mafalda can encode data using Base64 prior to exfiltration.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Mafalda can execute shell commands using `cmd.exe`.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1112 | Modify Registry | Mafalda can manipulate the system registry on a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1552.004 | Private KeysSub-technique | |
| Enterprise | T1569.002 | Service ExecutionSub-technique | Mafalda can create a remote service, let it run once, and then delete it.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1095 | Non-Application Layer Protocol | |
| Enterprise | T1074.001 | Local Data StagingSub-technique | |
| Enterprise | T1005 | Data from Local System | |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1059.001 | PowerShellSub-technique | Mafalda can execute PowerShell commands on a compromised machine.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1090.001 | Internal ProxySub-technique | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1057 | Process Discovery | |
| Enterprise | T1056 | Input Capture | Mafalda can conduct mouse event logging.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | |
| Enterprise | T1049 | System Network Connections Discovery | |
| Enterprise | T1012 | Query Registry | Mafalda can enumerate Registry keys with all subkeys and values.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1217 | Browser Information Discovery | |
| Enterprise | T1113 | Screen Capture | |
| Enterprise | T1041 | Exfiltration Over C2 Channel | |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1105 | Ingress Tool Transfer | Mafalda can download additional files onto the compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1016 | System Network Configuration Discovery | |
| Enterprise | T1033 | System Owner/User Discovery | Mafalda can collect the username from a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1680 | Local Storage Discovery | |
| Enterprise | T1134 | Access Token Manipulation | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1106 | Native API | |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1622 | Debugger Evasion | Mafalda can search for debugging tools on a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Mafalda can dump password hashes from `LSASS.exe`.CitationSentinelLabs Metador Technical Appendix Sept 2022 |
Groups, software, and campaigns
G1013: Metador
Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universities in the Middle East and Africa. Security researchers named the group Metador based on the "I am meta" string in one of the group's malware samples and the expectation of Spanish-language responses from C2 servers.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.2 | Current bundle | a42b5039b3df… | ||
| 19.1 | 1.2 | Older bundle | a42b5039b3df… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]SentinelLabs Metador Sept 2022
Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.
Open source URL - [2]mitre-attackS1060Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
