LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1222: RIFLESPINE

RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.CitationGoogle Cloud Mandiant UNC3886 2024

EnterpriseS1222MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

RIFLESPINE matters because it is a Linux-listed backdoor that uses Google Drive for both file transfer and command execution. For leaders, the business issue is not only malware on a host; it is whether trusted cloud storage traffic can become a command, control, staging, and exfiltration path without being noticed.

Executive priority

Prioritize validation of Linux monitoring, outbound web/cloud-storage governance, and incident response procedures for systems that are allowed to reach Google Drive or similar web services. This object is associated in ATT&CK with UNC3886, and its mapped behaviors span persistence, discovery, command and control, ingress transfer, collection staging, and cloud-storage exfiltration. Decision-makers should ask whether current controls can distinguish legitimate business use of cloud storage from suspicious automated transfer and command activity.

Technical view

ATT&CK provides no official detection text for RIFLESPINE, so defenders should validate coverage from the mapped techniques: Unix shell execution, web-protocol C2, local data staging, system information discovery, bidirectional web-service communication, ingress tool transfer, deobfuscation/decoding, systemd service persistence, exfiltration to cloud storage, and symmetric cryptography. On Linux systems, focus on process execution, shell command history where available, service creation or modification under systemd, unusual local staging paths, outbound HTTPS/web traffic patterns, and file movement involving Google Drive-related services.

Likely telemetry

  • Linux process execution and parent-child process data
  • Shell command logging where enabled
  • systemd unit file creation, modification, enablement, and service start events
  • File creation, modification, archive/staging activity, and unusual local directories
  • Outbound web proxy, DNS, firewall, and network flow records

Detection direction

  • Confirm whether Linux endpoints and servers actually produce process, file, and service telemetry sufficient to investigate ATT&CK techniques T1059.004, T1543.002, T1074.001, and T1082.
  • Tune network analytics for unusual automated access to cloud storage over web protocols, especially hosts or service accounts that do not normally interact with Google Drive.
  • Correlate cloud-storage upload/download activity with local staging, shell execution, new systemd services, and ingress file transfer rather than alerting on cloud access alone.
  • Treat encrypted or opaque outbound traffic as context, not proof; symmetric cryptography is mapped, but local baselines and proxy visibility determine detection value.
  • Account for false positives from legitimate backup, synchronization, administration, and developer workflows that use cloud storage or scripted web requests.

Mitigation priorities

  • Establish business-approved cloud storage use cases and restrict or monitor unapproved cloud-storage access from Linux servers and sensitive environments.
  • Harden Linux persistence surfaces by controlling who can create or modify systemd services and by monitoring service configuration changes.
  • Improve egress governance with proxy, DNS, and firewall visibility for outbound web traffic from critical hosts.
  • Maintain endpoint logging and retention sufficient for incident response reconstruction of shell execution, file staging, and tool transfer.
  • Use least privilege and segmentation to limit what a compromised Linux host can access, stage, and exfiltrate.
Additional notes and limits

The supplied ATT&CK relationship context ties RIFLESPINE to UNC3886 and to techniques across execution, command and control, collection, discovery, persistence, privilege escalation, exfiltration, and stealth. The most decision-relevant feature is use of a legitimate cloud service channel, because this can bypass simplistic blocking approaches and complicate SOC triage.

MITRE does not provide official detection guidance for this object in the supplied fields. The platform field lists Linux, while the description calls the malware cross-platform; this take therefore emphasizes Linux because that is the supplied platform. Local telemetry, cloud logging availability, and approved Google Drive usage are required to determine actual exposure or coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

RIFLESPINE

RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.CitationGoogle Cloud Mandiant UNC3886 2024

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
1bef797e8de83779...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.