ATT&CKSoftwarePowerStallion

PowerStallion

S0393

Malware.View on attack.mitre.org

About this malware

PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027
Obfuscated Files or Information

PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server.

T1057
Process Discovery

PowerStallion has been used to monitor process lists.

T1059.001
PowerShell

PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server.

T1070.006
Timestomp

PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file.

T1102.002
Bidirectional Communication

PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with net use.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Turla PowerShell May 2019 Open source
    Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.