Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0398
malware
HyperBro
HyperBro is a custom in-memory backdoor used by Threat Group-3390.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 13
uses
T1055
Process Injection
uses
T1574.001
DLL
uses
T1071.001
Web Protocols
uses
T1140
Deobfuscate/Decode Files or Infor…
uses
T1569.002
Service Execution
uses
T1007
System Service Discovery
uses
T1113
Screen Capture
uses
T1027.002
Software Packing
uses
T1106
Native API
uses
T1027.013
Encrypted/Encoded File
uses
T1105
Ingress Tool Transfer
uses
T1070.004
File Deletion
uses by
G0027
Threat Group-3390