Carbon

S0335

Malware.View on attack.mitre.org

About this malware

Carbon is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims. Carbon has been selectively used by Turla to target government and foreign affairs-related organizations in Central Asia.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1012
Query Registry

Carbon enumerates values in the Registry.

T1016
System Network Configuration Discovery

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1018
Remote System Discovery

Carbon uses the net view command.

T1027
Obfuscated Files or Information

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Carbon uses HTTP to send data to the C2 server.

T1049
System Network Connections Discovery

Carbon uses the netstat -r and netstat -an commands.

T1053.005
Scheduled Task

Carbon creates several tasks for later execution to continue persistence on the victim’s machine.

T1055.001
Dynamic-link Library Injection

Carbon has a command to inject code into a process.

T1057
Process Discovery

Carbon can list the processes on the victim’s machine.

T1069
Permission Groups Discovery

Carbon uses the net group command.

T1071.001
Web Protocols

Carbon can use HTTP in C2 communications.

T1074.001
Local Data Staging

Carbon creates a base directory that contains the files and folders that are collected.

T1095
Non-Application Layer Protocol

Carbon uses TCP and UDP for C2.

T1102
Web Service

Carbon can use Pastebin to receive C2 commands.

T1124
System Time Discovery

Carbon uses the command net time \\127.0.0.1 to get information the system’s time.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET Carbon Mar 2017 Open source
    ESET. (2017, March 30). Carbon Paper: Peering into Turla’s second stage backdoor. Retrieved November 7, 2018.
  2. Securelist Turla Oct 2018 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2018, October 04). Shedding Skin – Turla’s Fresh Faces. Retrieved November 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.