Tarrask

S1011

Malware.View on attack.mitre.org

About this malware

Tarrask is malware that has been used by HAFNIUM since at least August 2021. Tarrask was designed to evade digital defenses and maintain persistence by generating concealed scheduled tasks.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1036.004
Masquerade Task or Service

Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections.

T1036.005
Match Legitimate Resource Name or Location

Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`.

T1053.005
Scheduled Task

Tarrask is able to create “hidden” scheduled tasks for persistence.

T1059.003
Windows Command Shell

Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1112
Modify Registry

Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks.

T1134.001
Token Impersonation/Theft

Tarrask leverages token theft to obtain `lsass.exe` security permissions.

T1564
Hide Artifacts

Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Tarrask scheduled task Open source
    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.