ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareMosquito | Mosquito uses the |
| T1027.011 Fileless Storage |
MalwareMosquito | Mosquito stores configuration values under the Registry key |
| T1027.013 Encrypted/Encoded File |
MalwareMosquito | Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer. |
| T1033 System Owner/User Discovery |
MalwareMosquito | Mosquito runs |
| T1047 Windows Management Instrumentation |
MalwareMosquito | Mosquito's installer uses WMI to search for antivirus display names. |
| T1057 Process Discovery |
MalwareMosquito | Mosquito runs |
| T1059.001 PowerShell |
MalwareMosquito | Mosquito can launch PowerShell Scripts. |
| T1059.003 Windows Command Shell |
MalwareMosquito | Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server. |
| T1059.007 JavaScript |
GroupTurla | Turla has used various JavaScript-based backdoors. |
| T1070.004 File Deletion |
MalwareMosquito | Mosquito deletes files using DeleteFileW API call. |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareMosquito | Mosquito can upload and download files to the victim. |
| T1106 Native API |
MalwareMosquito | Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions. |
| T1112 Modify Registry |
MalwareMosquito | Mosquito can modify Registry keys under |
| T1204.001 Malicious Link |
GroupTurla | Turla has used spearphishing via a link to get users to download and run their malware. |
| T1218.011 Rundll32 |
MalwareMosquito | Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability. |
| T1518.001 Security Software Discovery |
MalwareMosquito | Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system. |
| T1546.015 Component Object Model Hijacking |
MalwareMosquito | Mosquito uses COM hijacking as a method of persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMosquito | Mosquito establishes persistence under the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupTurla | Turla established persistence by adding a Shell value under the Registry key |
| T1566.002 Spearphishing Link |
GroupTurla | Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access. |
| T1573.001 Symmetric Cryptography |
MalwareMosquito | Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.