Malware.View on attack.mitre.org
Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group. Torisma was discovered during an investigation into the 2020 Operation North Star campaign that targeted the defense sector.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address. |
| T1027.002 Software Packing |
Torisma has been packed with Iz4 compression. |
| T1027.013 Encrypted/Encoded File |
Torisma has been Base64 encoded and AES encrypted. |
| T1041 Exfiltration Over C2 Channel |
Torisma can send victim data to an actor-controlled C2 server. |
| T1049 System Network Connections Discovery |
Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections. |
| T1071.001 Web Protocols |
Torisma can use HTTP and HTTPS for C2 communications. |
| T1106 Native API |
Torisma has used various Windows API calls. |
| T1124 System Time Discovery |
Torisma can collect the current time on a victim machine. |
| T1132.001 Standard Encoding |
Torisma has encoded C2 communications with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
Torisma has used XOR and Base64 to decode C2 data. |
| T1480 Execution Guardrails |
Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list. |
| T1573.001 Symmetric Cryptography |
Torisma has encrypted its C2 communications using XOR and VEST-32. |
| T1680 Local Storage Discovery |
Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.