S1222: RIFLESPINE
RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.CitationGoogle Cloud Mandiant UNC3886 2024
Security context for executives and security teams
RIFLESPINE matters because it is a Linux-listed backdoor that uses Google Drive for both file transfer and command execution. For leaders, the business issue is not only malware on a host; it is whether trusted cloud storage traffic can become a command, control, staging, and exfiltration path without being noticed.
Executive priority
Prioritize validation of Linux monitoring, outbound web/cloud-storage governance, and incident response procedures for systems that are allowed to reach Google Drive or similar web services. This object is associated in ATT&CK with UNC3886, and its mapped behaviors span persistence, discovery, command and control, ingress transfer, collection staging, and cloud-storage exfiltration. Decision-makers should ask whether current controls can distinguish legitimate business use of cloud storage from suspicious automated transfer and command activity.
Technical view
ATT&CK provides no official detection text for RIFLESPINE, so defenders should validate coverage from the mapped techniques: Unix shell execution, web-protocol C2, local data staging, system information discovery, bidirectional web-service communication, ingress tool transfer, deobfuscation/decoding, systemd service persistence, exfiltration to cloud storage, and symmetric cryptography. On Linux systems, focus on process execution, shell command history where available, service creation or modification under systemd, unusual local staging paths, outbound HTTPS/web traffic patterns, and file movement involving Google Drive-related services.
Likely telemetry
- Linux process execution and parent-child process data
- Shell command logging where enabled
- systemd unit file creation, modification, enablement, and service start events
- File creation, modification, archive/staging activity, and unusual local directories
- Outbound web proxy, DNS, firewall, and network flow records
Detection direction
- Confirm whether Linux endpoints and servers actually produce process, file, and service telemetry sufficient to investigate ATT&CK techniques T1059.004, T1543.002, T1074.001, and T1082.
- Tune network analytics for unusual automated access to cloud storage over web protocols, especially hosts or service accounts that do not normally interact with Google Drive.
- Correlate cloud-storage upload/download activity with local staging, shell execution, new systemd services, and ingress file transfer rather than alerting on cloud access alone.
- Treat encrypted or opaque outbound traffic as context, not proof; symmetric cryptography is mapped, but local baselines and proxy visibility determine detection value.
- Account for false positives from legitimate backup, synchronization, administration, and developer workflows that use cloud storage or scripted web requests.
Mitigation priorities
- Establish business-approved cloud storage use cases and restrict or monitor unapproved cloud-storage access from Linux servers and sensitive environments.
- Harden Linux persistence surfaces by controlling who can create or modify systemd services and by monitoring service configuration changes.
- Improve egress governance with proxy, DNS, and firewall visibility for outbound web traffic from critical hosts.
- Maintain endpoint logging and retention sufficient for incident response reconstruction of shell execution, file staging, and tool transfer.
- Use least privilege and segmentation to limit what a compromised Linux host can access, stage, and exfiltrate.
Additional notes and limits
The supplied ATT&CK relationship context ties RIFLESPINE to UNC3886 and to techniques across execution, command and control, collection, discovery, persistence, privilege escalation, exfiltration, and stealth. The most decision-relevant feature is use of a legitimate cloud service channel, because this can bypass simplistic blocking approaches and complicate SOC triage.
MITRE does not provide official detection guidance for this object in the supplied fields. The platform field lists Linux, while the description calls the malware cross-platform; this take therefore emphasizes Linux because that is the supplied platform. Local telemetry, cloud logging availability, and approved Google Drive usage are required to determine actual exposure or coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
RIFLESPINE
RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.CitationGoogle Cloud Mandiant UNC3886 2024
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
