FireEye Labs. (2015, July). HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Group. Retrieved November 17, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareHAMMERTOSS | HAMMERTOSS is controlled via commands that are appended to image files. |
| T1059.001 PowerShell |
MalwareHAMMERTOSS | HAMMERTOSS is known to use PowerShell. |
| T1071.001 Web Protocols |
MalwareHAMMERTOSS | The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands. |
| T1102.003 One-Way Communication |
MalwareHAMMERTOSS | The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day. |
| T1564.003 Hidden Window |
MalwareHAMMERTOSS | HAMMERTOSS has used |
| T1567.002 Exfiltration to Cloud Storage |
MalwareHAMMERTOSS | HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| T1573.001 Symmetric Cryptography |
MalwareHAMMERTOSS | Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command. |
| T1583.006 Web Services |
GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.