ATT&CKReferencesESET Turla Mosquito Jan 2018

ESET Turla Mosquito Jan 2018

ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMosquito

Mosquito uses the ipconfig command.

T1027.011
Fileless Storage
MalwareMosquito

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

T1027.013
Encrypted/Encoded File
MalwareMosquito

Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer.

T1033
System Owner/User Discovery
MalwareMosquito

Mosquito runs whoami on the victim’s machine.

T1047
Windows Management Instrumentation
MalwareMosquito

Mosquito's installer uses WMI to search for antivirus display names.

T1057
Process Discovery
MalwareMosquito

Mosquito runs tasklist to obtain running processes.

T1059.001
PowerShell
MalwareMosquito

Mosquito can launch PowerShell Scripts.

T1059.003
Windows Command Shell
MalwareMosquito

Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server.

T1059.007
JavaScript
GroupTurla

Turla has used various JavaScript-based backdoors.

T1070.004
File Deletion
MalwareMosquito

Mosquito deletes files using DeleteFileW API call.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1102.002
Bidirectional Communication
GroupTurla

A Turla JavaScript backdoor has used Google Apps Script as its C2 server.

T1105
Ingress Tool Transfer
MalwareMosquito

Mosquito can upload and download files to the victim.

T1106
Native API
MalwareMosquito

Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions.

T1112
Modify Registry
MalwareMosquito

Mosquito can modify Registry keys under HKCU\Software\Microsoft\[dllname] to store configuration values. Mosquito also modifies Registry keys under HKCR\CLSID\...\InprocServer32 with a path to the launcher.

T1204.001
Malicious Link
GroupTurla

Turla has used spearphishing via a link to get users to download and run their malware.

T1218.011
Rundll32
MalwareMosquito

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1518.001
Security Software Discovery
MalwareMosquito

Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system.

T1546.015
Component Object Model Hijacking
MalwareMosquito

Mosquito uses COM hijacking as a method of persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareMosquito

Mosquito establishes persistence under the Registry key HKCU\Software\Run auto_update.

T1547.004
Winlogon Helper DLL
GroupTurla

Turla established persistence by adding a Shell value under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1566.002
Spearphishing Link
GroupTurla

Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access.

T1573.001
Symmetric Cryptography
MalwareMosquito

Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.