RaqibCTI
malware

LITTLELAMB.WOOLTEA

S1121 · ATT&CK v19.2
Platforms
Network Devices
Tracked actors
0

View on attack.mitre.org ↗

Description

[LITTLELAMB.WOOLTEA](https://attack.mitre.org/software/S1121) is a backdoor that was used by UNC5325 during [Cutting Edge](https://attack.mitre.org/campaigns/C0029) to deploy malware on targeted Ivanti Connect Secure VPNs and to establish persistence across system upgrades and patches.(Citation: Mandiant Cutting Edge Part 3 February 2024)

Actors that use this

0 tracked actors
No tracked actor uses this yet
Not linked to any of our tracked MENA actors in actor_software — still browsable via the ATT&CK dictionary above.