ATT&CKReferencesKaspersky Turla

Kaspersky Turla

Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareEpic

Epic uses the tasklist /svc command to list the services on the system.

T1007
System Service Discovery
GroupTurla

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1012
Query Registry
MalwareEpic

Epic uses the rem reg query command to obtain values from Registry keys.

T1012
Query Registry
GroupTurla

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1014
Rootkit
MalwareUroburos

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

T1016
System Network Configuration Discovery
MalwareEpic

Epic uses the nbtstat -n and nbtstat -s commands on the victim’s machine.

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1018
Remote System Discovery
GroupTurla

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1018
Remote System Discovery
MalwareEpic

Epic uses the net view command on the victim’s machine.

T1021.002
SMB/Windows Admin Shares
GroupTurla

Turla used net use commands to connect to lateral systems within a network.

T1027
Obfuscated Files or Information
MalwareEpic

Epic heavily obfuscates its code to make analysis more difficult.

T1049
System Network Connections Discovery
MalwareEpic

Epic uses the net use, net session, and netstat commands to gather information on network connections.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1057
Process Discovery
MalwareEpic

Epic uses the tasklist /v command to obtain a list of processes.

T1071.001
Web Protocols
MalwareEpic

Epic uses HTTP and HTTPS for C2 communications.

T1082
System Information Discovery
GroupTurla

Turla surveys a system upon check-in to discover operating system configuration details using the systeminfo and set commands.

T1083
File and Directory Discovery
GroupTurla

Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the lPH*.dll pattern.

T1083
File and Directory Discovery
MalwareEpic

Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories.

T1110
Brute Force
GroupTurla

Turla may attempt to connect to systems within a victim's network using net use commands and a predefined list or collection of passwords.

T1124
System Time Discovery
GroupTurla

Turla surveys a system upon check-in to discover the system time by using the net time command.

T1124
System Time Discovery
MalwareEpic

Epic uses the net time command to get the system time from the machine and collect the current date and time zone information.

T1518.001
Security Software Discovery
MalwareEpic

Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them.

T1553.002
Code Signing
MalwareEpic

Turla has used valid digital certificates from Sysprint AG to sign its Epic dropper.

T1560
Archive Collected Data
MalwareEpic

Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.

T1573.001
Symmetric Cryptography
MalwareEpic

Epic encrypts commands from the C2 server using a hardcoded key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.