Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupTurla | Turla RPC backdoors can upload files from victim machines. |
| T1012 Query Registry |
GroupTurla | Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1025 Data from Removable Media |
GroupTurla | Turla RPC backdoors can collect files from USB thumb drives. |
| T1027 Obfuscated Files or Information |
MalwarePowerStallion | PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server. |
| T1027.010 Command Obfuscation |
GroupTurla | Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.011 Fileless Storage |
GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1055 Process Injection |
GroupTurla | Turla has also used PowerSploit's |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1057 Process Discovery |
MalwarePowerStallion | PowerStallion has been used to monitor process lists. |
| T1059.001 PowerShell |
MalwarePowerStallion | PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server. |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1059.003 Windows Command Shell |
GroupTurla | Turla RPC backdoors have used cmd.exe to execute commands. |
| T1070.006 Timestomp |
MalwarePowerStallion | PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file. |
| T1083 File and Directory Discovery |
GroupTurla | Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the |
| T1090 Proxy |
GroupTurla | Turla RPC backdoors have included local UPnP RPC proxies. |
| T1102.002 Bidirectional Communication |
MalwarePowerStallion | PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with |
| T1106 Native API |
GroupTurla | Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes. |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1134.002 Create Process with Token |
GroupTurla | Turla RPC backdoors can impersonate or steal process tokens before executing commands. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTurla | Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupTurla | Turla has used WMI event filters and consumers to establish persistence. |
| T1546.013 PowerShell Profile |
GroupTurla | Turla has used PowerShell profiles to maintain persistence on an infected machine. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1685 Disable or Modify Tools |
GroupTurla | Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.