QUIETEXIT
The MITRE Corporation
· Published 16/12/2025 19:36 · Modified 27/03/2026 01:03
Family
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 16/12/2025 19:36
- Modified
- 27/03/2026 01:03
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 25 attack patterns (mitre), 1 intrusion sets (apt), 3 indicators, 1 reports
Description
[QUIETEXIT](https://attack.mitre.org/software/S1084) is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by [APT29](https://attack.mitre.org/groups/G0016) since at least 2021. [APT29](https://attack.mitre.org/groups/G0016) has deployed [QUIETEXIT](https://attack.mitre.org/software/S1084) on opaque network appliances that typically don't support antivirus or endpoint detection and response tools within a victim environment.(Citation: Mandiant APT29 Eye Spy Email Nov 22)
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (25)
-
T1016 usesSystem Network Configuration Discovery
-
T1095 usesNon-Application Layer Protocol
-
T1027 usesObfuscated Files or Information
-
T1008 usesFallback Channels
-
T1090 usesProxy
-
T1036 usesMasquerading
-
T1098 usesAccount Manipulation
-
T1608 usesStage Capabilities
-
T1111 usesMulti-Factor Authentication Interception
-
T1021 usesRemote Services
-
T1037 usesBoot or Logon Initialization Scripts
-
T1057 usesProcess Discovery
-
T1090.002 usesExternal Proxy
-
T1114 usesEmail Collection
-
T1572 usesProtocol Tunneling
-
T1518 usesSoftware Discovery
-
T1583 usesAcquire Infrastructure
-
T1003 usesOS Credential Dumping
-
T1071 usesApplication Layer Protocol
-
T1573 usesEncrypted Channel
-
T1049 usesSystem Network Connections Discovery
-
T1505 usesServer Software Component
-
T1012 usesQuery Registry
-
T1584 usesCompromise Infrastructure
-
T1036.005 usesMatch Legitimate Resource Name or Location
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33
Indicators (3)
Reports (1)
-
Confidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 ToolsPublished 29/05/2026 11:51 · threat-report