LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1060: Mafalda

Mafalda is a flexible interactive implant that has been used by Metador. Security researchers assess the Mafalda name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s. [1]

EnterpriseS1060MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S1060: Mafalda describes [Mafalda](https://attack.mitre.org/software/S1060) is a flexible interactive implant that has been used by [Metador](https://attack.mitre.org/groups/G1013). Security researchers assess the [Mafalda](https://attack.mitre.org/software/S1060) name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s. (Citation: SentinelLabs Metador Sept 2022)

Executive priority

S1060: Mafalda is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S1060: Mafalda by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S1060: Mafalda appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Mafalda

Mafalda is a flexible interactive implant that has been used by Metador. Security researchers assess the Mafalda name may be inspired by an Argentinian cartoon character that has been popular as a means of political commentary since the 1960s. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

36 rows
DomainIDNameRelationship / procedure
EnterpriseT1205.001Port KnockingSub-technique

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.[1]CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1134.003Make and Impersonate TokenSub-technique

Mafalda can create a token for a different user.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1133External Remote Services

Mafalda can establish an SSH connection from a compromised host to a server.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions.[1]

EnterpriseT1132.001Standard EncodingSub-technique

Mafalda can encode data using Base64 prior to exfiltration.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1059.003Windows Command ShellSub-technique

Mafalda can execute shell commands using `cmd.exe`.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1112Modify Registry

Mafalda can manipulate the system registry on a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1552.004Private KeysSub-technique

Mafalda can collect a Chrome encryption key used to protect browser cookies.[1]

EnterpriseT1569.002Service ExecutionSub-technique

Mafalda can create a remote service, let it run once, and then delete it.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1095Non-Application Layer Protocol

Mafalda can use raw TCP for C2.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Mafalda can place retrieved files into a destination directory.[1]

EnterpriseT1005Data from Local System

Mafalda can collect files and information from a compromised host.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Mafalda can decrypt files and data.[1]

EnterpriseT1059.001PowerShellSub-technique

Mafalda can execute PowerShell commands on a compromised machine.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1090.001Internal ProxySub-technique

Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1057Process Discovery

Mafalda can enumerate running processes on a machine.[1]

EnterpriseT1056Input Capture

Mafalda can conduct mouse event logging.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1071.001Web ProtocolsSub-technique

Mafalda can use HTTP for C2.[1]

EnterpriseT1049System Network Connections Discovery

Mafalda can use the GetExtendedTcpTable function to retrieve information about established TCP connections.[1]

EnterpriseT1012Query Registry

Mafalda can enumerate Registry keys with all subkeys and values.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1217Browser Information Discovery

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.[1]

EnterpriseT1113Screen Capture

Mafalda can take a screenshot of the target machine and save it to a file.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Mafalda can send network system data and files to its C2 server.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Mafalda can encrypt its C2 traffic with RC4.[1]

EnterpriseT1082System Information Discovery

Mafalda can collect the computer name of a compromised host.[1]CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1105Ingress Tool Transfer

Mafalda can download additional files onto the compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1016System Network Configuration Discovery

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.[1]

EnterpriseT1033System Owner/User Discovery

Mafalda can collect the username from a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1680Local Storage Discovery

Mafalda can enumerate all drives on a compromised host.[1]CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1134Access Token Manipulation

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1106Native API

Mafalda can use a variety of API calls.[1]

EnterpriseT1083File and Directory Discovery

Mafalda can search for files and directories.[1]

EnterpriseT1622Debugger Evasion

Mafalda can search for debugging tools on a compromised host.CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1518.001Security Software DiscoverySub-technique

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.[1]CitationSentinelLabs Metador Technical Appendix Sept 2022

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Mafalda has been obfuscated and contains encrypted functions.[1]

EnterpriseT1003.001LSASS MemorySub-technique

Mafalda can dump password hashes from `LSASS.exe`.CitationSentinelLabs Metador Technical Appendix Sept 2022

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1013: Metador

Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universities in the Middle East and Africa. Security researchers named the group Metador based on the "I am meta" string in one of the group's malware samples and the expectation of Spanish-language responses from C2 servers.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.2
Created
Modified
Raw hash
a42b5039b3df6ea9...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.2Current bundlea42b5039b3df…
19.11.2Older bundlea42b5039b3df…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SentinelLabs Metador Sept 2022

    Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.

    Open source URL
  2. [2]
    mitre-attackS1060
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.