Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareTarrask | Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTarrask | Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`. |
| T1053.005 Scheduled Task |
MalwareTarrask | Tarrask is able to create “hidden” scheduled tasks for persistence. |
| T1059.003 Windows Command Shell |
MalwareTarrask | Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks. |
| T1112 Modify Registry |
MalwareTarrask | Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks. |
| T1134.001 Token Impersonation/Theft |
MalwareTarrask | Tarrask leverages token theft to obtain `lsass.exe` security permissions. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1564 Hide Artifacts |
MalwareTarrask | Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.