Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0216
malware
POORAIM
POORAIM is a backdoor used by APT37 in campaigns since at least 2014.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 7
uses
T1083
File and Directory Discovery
uses
T1113
Screen Capture
uses
T1102.002
Bidirectional Communication
uses
T1057
Process Discovery
uses
T1082
System Information Discovery
uses
T1189
Drive-by Compromise
uses by
G0067
APT37