C0026

C0026

Campaign, Aug 2022 to Sep 2022.View on attack.mitre.org

About this campaign

C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains. Several tools and tactics used during C0026 were consistent with historic Turla operations.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1005
Data from Local System

During C0026, the threat actors collected documents from compromised hosts.

T1030
Data Transfer Size Limits

During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.

T1105
Ingress Tool Transfer

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.

T1560.001
Archive via Utility

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

T1568
Dynamic Resolution

During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.

T1583.001
Domains

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software6

References1

  1. Mandiant Suspected Turla Campaign February 2023 Open source
    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.