logo

Backscatter: Automated Configuration Extraction

ID: 11c2d6e8-80e9-5d2a-954b-d1dfbf572bef

STIX ID: report--11c2d6e8-80e9-5d2a-954b-d1dfbf572bef

Feed Name: Google Cloud Threat Intelligence

Date Published: 2025-01-14

Date Updated: 2026-04-27

Author: Mandiant

...
...

Backscatter is a static-analysis tool from Mandiant FLARE integrated into Google Threat Intelligence and VirusTotal that extracts malware configurations and indicators of compromise without executing samples. It complements dynamic analysis by identifying embedded IOCs, C2 servers, dropped files, and configuration attributes—enabling faster, high-confidence malware family attribution and improved IOC pivoting within the platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.