Gazer

S0168

Malware.View on attack.mitre.org

About this malware

Gazer is a backdoor used by Turla since at least 2016.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources.

T1033
System Owner/User Discovery

Gazer obtains the current user's security identifier.

T1053.005
Scheduled Task

Gazer can establish persistence by creating a scheduled task.

T1055
Process Injection

Gazer injects its communication module into an Internet accessible process through which it performs C2.

T1055.003
Thread Execution Hijacking

Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.

T1070.004
File Deletion

Gazer has commands to delete files and persistence mechanisms from the victim.

T1070.006
Timestomp

For early Gazer versions, the compilation timestamp was faked.

T1071.001
Web Protocols

Gazer communicates with its C2 servers over HTTP.

T1105
Ingress Tool Transfer

Gazer can execute a task to download a file.

T1480.002
Mutual Exclusion

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1546.002
Screensaver

Gazer can establish persistence through the system screensaver by configuring it to execute the malware.

T1547.001
Registry Run Keys / Startup Folder

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.004
Winlogon Helper DLL

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.009
Shortcut Modification

Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe.

T1553.002
Code Signing

Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd."

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Gazer Aug 2017 Open source
    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.