Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections. |
| T1036.005 Match Legitimate Resource Name or Location |
Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`. |
| T1053.005 Scheduled Task |
Tarrask is able to create “hidden” scheduled tasks for persistence. |
| T1059.003 Windows Command Shell |
Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks. |
| T1112 Modify Registry |
Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks. |
| T1134.001 Token Impersonation/Theft |
Tarrask leverages token theft to obtain `lsass.exe` security permissions. |
| T1564 Hide Artifacts |
Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.