ATT&CKReferencesTalos TinyTurla September 2021

Talos TinyTurla September 2021

Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTinyTurla

TinyTurla can upload files from a compromised host.

T1008
Fallback Channels
MalwareTinyTurla

TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds.

T1012
Query Registry
MalwareTinyTurla

TinyTurla can query the Registry for its configuration information.

T1027.011
Fileless Storage
MalwareTinyTurla

TinyTurla can save its configuration parameters in the Registry.

T1029
Scheduled Transfer
MalwareTinyTurla

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.

T1036.004
Masquerade Task or Service
MalwareTinyTurla

TinyTurla has mimicked an existing Windows service by being installed as Windows Time Service.

T1036.005
Match Legitimate Resource Name or Location
MalwareTinyTurla

TinyTurla has been deployed as `w64time.dll` to appear legitimate.

T1059.003
Windows Command Shell
MalwareTinyTurla

TinyTurla has been installed using a .bat file.

T1071.001
Web Protocols
MalwareTinyTurla

TinyTurla can use HTTPS in C2 communications.

T1090.001
Internal Proxy
GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

T1105
Ingress Tool Transfer
MalwareTinyTurla

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.

T1106
Native API
MalwareTinyTurla

TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions.

T1112
Modify Registry
MalwareTinyTurla

TinyTurla can set its configuration parameters in the Registry.

T1569.002
Service Execution
MalwareTinyTurla

TinyTurla can install itself as a service on compromised machines.

T1573.002
Asymmetric Cryptography
MalwareTinyTurla

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.