ATT&CKReferencesESET Gazer Aug 2017

ESET Gazer Aug 2017

ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.005
Indicator Removal from Tools
GroupTurla

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

T1053.005
Scheduled Task
MalwareGazer

Gazer can establish persistence by creating a scheduled task.

T1055
Process Injection
MalwareGazer

Gazer injects its communication module into an Internet accessible process through which it performs C2.

T1055.003
Thread Execution Hijacking
MalwareGazer

Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.

T1070.004
File Deletion
MalwareGazer

Gazer has commands to delete files and persistence mechanisms from the victim.

T1070.006
Timestomp
MalwareGazer

For early Gazer versions, the compilation timestamp was faked.

T1071.001
Web Protocols
MalwareGazer

Gazer communicates with its C2 servers over HTTP.

T1105
Ingress Tool Transfer
MalwareGazer

Gazer can execute a task to download a file.

T1480.002
Mutual Exclusion
MalwareGazer

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1546.002
Screensaver
MalwareGazer

Gazer can establish persistence through the system screensaver by configuring it to execute the malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.004
Winlogon Helper DLL
MalwareGazer

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.009
Shortcut Modification
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe.

T1553.002
Code Signing
MalwareGazer

Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd."

T1564.004
NTFS File Attributes
MalwareGazer

Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible.

T1573.001
Symmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses 3DES.

T1573.002
Asymmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.