ATT&CKReferencesMandiant Suspected Turla Campaign February 2023

Mandiant Suspected Turla Campaign February 2023

Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns1

Procedure examples35

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignC0026

During C0026, the threat actors collected documents from compromised hosts.

T1005
Data from Local System
MalwareKOPILUWAK

KOPILUWAK can gather information from compromised hosts.

T1012
Query Registry
MalwareQUIETCANARY

QUIETCANARY has the ability to retrieve information from the Registry.

T1016
System Network Configuration Discovery
MalwareKOPILUWAK

KOPILUWAK can use Arp to discover a target's network configuration setttings.

T1016
System Network Configuration Discovery
MalwareQUIETCANARY

QUIETCANARY can identify the default proxy setting on a compromised host.

T1030
Data Transfer Size Limits
CampaignC0026

During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.

T1033
System Owner/User Discovery
MalwareKOPILUWAK

KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details.

T1036.005
Match Legitimate Resource Name or Location
MalwareANDROMEDA

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

T1036.008
Masquerade File Type
MalwareANDROMEDA

ANDROMEDA has been delivered through a LNK file disguised as a folder.

T1041
Exfiltration Over C2 Channel
MalwareKOPILUWAK

KOPILUWAK has exfiltrated collected data to its C2 via POST requests.

T1049
System Network Connections Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections.

T1055
Process Injection
MalwareANDROMEDA

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

T1057
Process Discovery
MalwareKOPILUWAK

KOPILUWAK can enumerate current running processes on the targeted machine.

T1059.007
JavaScript
MalwareKOPILUWAK

KOPILUWAK had used Javascript to perform its core functions.

T1071.001
Web Protocols
MalwareANDROMEDA

ANDROMEDA has the ability to make GET requests to download files from C2.

T1071.001
Web Protocols
MalwareKOPILUWAK

KOPILUWAK has used HTTP POST requests to send data to C2.

T1071.001
Web Protocols
MalwareQUIETCANARY

QUIETCANARY can use HTTPS for C2 communications.

T1074
Data Staged
MalwareQUIETCANARY

QUIETCANARY has the ability to stage data prior to exfiltration.

T1074.001
Local Data Staging
MalwareKOPILUWAK

KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine.

T1091
Replication Through Removable Media
MalwareANDROMEDA

ANDROMEDA has been spread via infected USB keys.

T1105
Ingress Tool Transfer
CampaignC0026

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.

T1105
Ingress Tool Transfer
MalwareANDROMEDA

ANDROMEDA can download additional payloads from C2.

T1106
Native API
MalwareQUIETCANARY

QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer.

T1132.001
Standard Encoding
MalwareQUIETCANARY

QUIETCANARY can base64 encode C2 communications.

T1135
Network Share Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat and Net to discover network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareQUIETCANARY

QUIETCANARY can use a custom parsing routine to decode the command codes and additional parameters from the C2 before executing them.

T1204.002
Malicious File
MalwareKOPILUWAK

KOPILUWAK has gained execution through malicious attachments.

T1547.001
Registry Run Keys / Startup Folder
MalwareANDROMEDA

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

T1560.001
Archive via Utility
CampaignC0026

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

T1564.003
Hidden Window
MalwareQUIETCANARY

QUIETCANARY can execute processes in a hidden window.

T1566.001
Spearphishing Attachment
MalwareKOPILUWAK

KOPILUWAK has been delivered to victims as a malicious email attachment.

T1568
Dynamic Resolution
CampaignC0026

During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.

T1573.001
Symmetric Cryptography
MalwareQUIETCANARY

QUIETCANARY can RC4 encrypt C2 communications.

T1583.001
Domains
CampaignC0026

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

T1680
Local Storage Discovery
MalwareKOPILUWAK

KOPILUWAK can discover logical drive information on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.