ESET. (2017, March 30). Carbon Paper: Peering into Turla’s second stage backdoor. Retrieved November 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCarbon | Carbon enumerates values in the Registry. |
| T1016 System Network Configuration Discovery |
MalwareCarbon | Carbon can collect the IP address of the victims and other computers on the network using the commands: |
| T1027 Obfuscated Files or Information |
MalwareCarbon | Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCarbon | Carbon uses HTTP to send data to the C2 server. |
| T1053.005 Scheduled Task |
MalwareCarbon | Carbon creates several tasks for later execution to continue persistence on the victim’s machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarbon | Carbon has a command to inject code into a process. |
| T1057 Process Discovery |
MalwareCarbon | Carbon can list the processes on the victim’s machine. |
| T1074.001 Local Data Staging |
MalwareCarbon | Carbon creates a base directory that contains the files and folders that are collected. |
| T1095 Non-Application Layer Protocol |
MalwareCarbon | Carbon uses TCP and UDP for C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCarbon | Carbon decrypts task and configuration files for execution. |
| T1543.003 Windows Service |
MalwareCarbon | Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.