Campaign, Aug 2022 to Sep 2022.View on attack.mitre.org
C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains. Several tools and tactics used during C0026 were consistent with historic Turla operations.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
During C0026, the threat actors collected documents from compromised hosts. |
| T1030 Data Transfer Size Limits |
During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration. |
| T1105 Ingress Tool Transfer |
During C0026, the threat actors downloaded malicious payloads onto select compromised hosts. |
| T1560.001 Archive via Utility |
During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
| T1568 Dynamic Resolution |
During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA. |
| T1583.001 Domains |
For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.