Malware.View on attack.mitre.org
Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB) associated with the Turla toolset to collect intelligence on sensitive targets worldwide. Uroburos has several variants and has undergone nearly constant upgrade since its initial development in 2003 to keep it viable after public disclosures. Uroburos is typically deployed to external-facing nodes on a targeted network and has the ability to leverage additional tools and TTPs to further exploit an internal network. Uroburos has interoperable implants for Windows, Linux, and macOS, employs a high level of stealth in communications and architecture, and can easily incorporate new or replacement components.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests. |
| T1001.003 Protocol or Service Impersonation |
Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic. |
| T1005 Data from Local System |
Uroburos can use its `Get` command to exfiltrate specified files from the compromised system. |
| T1008 Fallback Channels |
Uroburos can use up to 10 channels to communicate between implants. |
| T1012 Query Registry |
Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader. |
| T1014 Rootkit |
Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components. |
| T1027.002 Software Packing |
Uroburos uses a custom packer. |
| T1027.009 Embedded Payloads |
The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation. |
| T1027.011 Fileless Storage |
Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.` |
| T1027.013 Encrypted/Encoded File |
Uroburos can use AES and CAST-128 encryption to obfuscate resources. |
| T1036.004 Masquerade Task or Service |
Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service. |
| T1055.001 Dynamic-link Library Injection |
Uroburos can use DLL injection to load embedded files and modules. |
| T1057 Process Discovery |
Uroburos can use its `Process List` command to enumerate processes on compromised hosts. |
| T1059.003 Windows Command Shell |
Uroburos has the ability to use the command line for execution on the targeted system. |
| T1070.004 File Deletion |
Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.