Malware.View on attack.mitre.org
TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.
| Technique | Procedure example |
|---|---|
| T1055.004 Asynchronous Procedure Call |
TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection." |
| T1059.003 Windows Command Shell |
TURNEDUP is capable of creating a reverse shell. |
| T1082 System Information Discovery |
TURNEDUP is capable of gathering system information. |
| T1105 Ingress Tool Transfer |
TURNEDUP is capable of downloading additional files. |
| T1113 Screen Capture |
TURNEDUP is capable of taking screenshots. |
| T1547.001 Registry Run Keys / Startup Folder |
TURNEDUP is capable of writing to a Registry Run key to establish. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.