Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0221
malware
Umbreon
A Linux rootkit that provides backdoor access and hides from defenders.
Platforms
Linux
MITRE ATT&CK ↗
Linked entities · 5
uses
T1059.003
Windows Command Shell
uses
T1014
Rootkit
uses
T1205
Traffic Signaling
uses
T1095
Non-Application Layer Protocol
uses
T1078.003
Local Accounts