RaqibCTI
malware

Kevin

S1020 · ATT&CK v19.2
Platforms
Windows
Tracked actors
1

View on attack.mitre.org ↗

Description

[Kevin](https://attack.mitre.org/software/S1020) is a backdoor implant written in C++ that has been used by [HEXANE](https://attack.mitre.org/groups/G1001) since at least June 2020, including in operations against organizations in Tunisia.(Citation: Kaspersky Lyceum October 2021)

Actors that use this

1 tracked actor
HEXANE (Lyceum)ATT&CK-attributed