Threat group.View on attack.mitre.org
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Turla RPC backdoors can upload files from victim machines. |
| T1007 System Service Discovery |
Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1012 Query Registry |
Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1016 System Network Configuration Discovery |
Turla surveys a system upon check-in to discover network configuration details using the |
| T1016.001 Internet Connection Discovery |
Turla has used |
| T1018 Remote System Discovery |
Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1021.002 SMB/Windows Admin Shares |
Turla used |
| T1025 Data from Removable Media |
Turla RPC backdoors can collect files from USB thumb drives. |
| T1027.005 Indicator Removal from Tools |
Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe. |
| T1027.010 Command Obfuscation |
Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.011 Fileless Storage |
Turla has used the Registry to store encrypted and encoded payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1049 System Network Connections Discovery |
Turla surveys a system upon check-in to discover active local network connections using the |
| T1055 Process Injection |
Turla has also used PowerSploit's |
| T1055.001 Dynamic-link Library Injection |
Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.