ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.005 Indicator Removal from Tools |
GroupTurla | Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe. |
| T1053.005 Scheduled Task |
MalwareGazer | Gazer can establish persistence by creating a scheduled task. |
| T1055 Process Injection |
MalwareGazer | Gazer injects its communication module into an Internet accessible process through which it performs C2. |
| T1055.003 Thread Execution Hijacking |
MalwareGazer | Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process. |
| T1070.004 File Deletion |
MalwareGazer | Gazer has commands to delete files and persistence mechanisms from the victim. |
| T1070.006 Timestomp |
MalwareGazer | For early Gazer versions, the compilation timestamp was faked. |
| T1071.001 Web Protocols |
MalwareGazer | Gazer communicates with its C2 servers over HTTP. |
| T1105 Ingress Tool Transfer |
MalwareGazer | Gazer can execute a task to download a file. |
| T1480.002 Mutual Exclusion |
MalwareGazer | Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running. |
| T1546.002 Screensaver |
MalwareGazer | Gazer can establish persistence through the system screensaver by configuring it to execute the malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu. |
| T1547.004 Winlogon Helper DLL |
MalwareGazer | Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key |
| T1547.009 Shortcut Modification |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe. |
| T1553.002 Code Signing |
MalwareGazer | Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd." |
| T1564.004 NTFS File Attributes |
MalwareGazer | Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible. |
| T1573.001 Symmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses 3DES. |
| T1573.002 Asymmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.