Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignC0026 | During C0026, the threat actors collected documents from compromised hosts. |
| T1005 Data from Local System |
MalwareKOPILUWAK | KOPILUWAK can gather information from compromised hosts. |
| T1012 Query Registry |
MalwareQUIETCANARY | QUIETCANARY has the ability to retrieve information from the Registry. |
| T1016 System Network Configuration Discovery |
MalwareKOPILUWAK | KOPILUWAK can use Arp to discover a target's network configuration setttings. |
| T1016 System Network Configuration Discovery |
MalwareQUIETCANARY | QUIETCANARY can identify the default proxy setting on a compromised host. |
| T1030 Data Transfer Size Limits |
CampaignC0026 | During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration. |
| T1033 System Owner/User Discovery |
MalwareKOPILUWAK | KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareANDROMEDA | ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| T1036.008 Masquerade File Type |
MalwareANDROMEDA | ANDROMEDA has been delivered through a LNK file disguised as a folder. |
| T1041 Exfiltration Over C2 Channel |
MalwareKOPILUWAK | KOPILUWAK has exfiltrated collected data to its C2 via POST requests. |
| T1049 System Network Connections Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections. |
| T1055 Process Injection |
MalwareANDROMEDA | ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| T1057 Process Discovery |
MalwareKOPILUWAK | KOPILUWAK can enumerate current running processes on the targeted machine. |
| T1059.007 JavaScript |
MalwareKOPILUWAK | KOPILUWAK had used Javascript to perform its core functions. |
| T1071.001 Web Protocols |
MalwareANDROMEDA | ANDROMEDA has the ability to make GET requests to download files from C2. |
| T1071.001 Web Protocols |
MalwareKOPILUWAK | KOPILUWAK has used HTTP POST requests to send data to C2. |
| T1071.001 Web Protocols |
MalwareQUIETCANARY | QUIETCANARY can use HTTPS for C2 communications. |
| T1074 Data Staged |
MalwareQUIETCANARY | QUIETCANARY has the ability to stage data prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareKOPILUWAK | KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine. |
| T1091 Replication Through Removable Media |
MalwareANDROMEDA | ANDROMEDA has been spread via infected USB keys. |
| T1105 Ingress Tool Transfer |
CampaignC0026 | During C0026, the threat actors downloaded malicious payloads onto select compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareANDROMEDA | ANDROMEDA can download additional payloads from C2. |
| T1106 Native API |
MalwareQUIETCANARY | QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer. |
| T1132.001 Standard Encoding |
MalwareQUIETCANARY | QUIETCANARY can base64 encode C2 communications. |
| T1135 Network Share Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat and Net to discover network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQUIETCANARY | QUIETCANARY can use a custom parsing routine to decode the command codes and additional parameters from the C2 before executing them. |
| T1204.002 Malicious File |
MalwareKOPILUWAK | KOPILUWAK has gained execution through malicious attachments. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareANDROMEDA | ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on. |
| T1560.001 Archive via Utility |
CampaignC0026 | During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
| T1564.003 Hidden Window |
MalwareQUIETCANARY | QUIETCANARY can execute processes in a hidden window. |
| T1566.001 Spearphishing Attachment |
MalwareKOPILUWAK | KOPILUWAK has been delivered to victims as a malicious email attachment. |
| T1568 Dynamic Resolution |
CampaignC0026 | During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA. |
| T1573.001 Symmetric Cryptography |
MalwareQUIETCANARY | QUIETCANARY can RC4 encrypt C2 communications. |
| T1583.001 Domains |
CampaignC0026 | For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
| T1680 Local Storage Discovery |
MalwareKOPILUWAK | KOPILUWAK can discover logical drive information on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.