ATT&CKReferencesAccenture HyperStack October 2020

Accenture HyperStack October 2020

Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1071.001
Web Protocols
MalwareCarbon

Carbon can use HTTP in C2 communications.

T1078.001
Default Accounts
MalwareHyperStack

HyperStack can use default credentials to connect to IPC$ shares on remote machines.

T1087.001
Local Account
MalwareHyperStack

HyperStack can enumerate all account names on a remote share.

T1090.001
Internal Proxy
MalwareKazuar

Kazuar has used internal nodes on the compromised network for C2 communications.

T1102
Web Service
MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

T1102
Web Service
GroupTurla

Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications.

T1106
Native API
MalwareHyperStack

HyperStack can use Windows API's ConnectNamedPipe and WNetAddConnection2 to detect incoming connections and connect to remote shares.

T1112
Modify Registry
MalwareHyperStack

HyperStack can add the name of its communication pipe to HKLM\SYSTEM\\CurrentControlSet\\Services\\lanmanserver\\parameters\NullSessionPipes.

T1140
Deobfuscate/Decode Files or Information
MalwareCarbon

Carbon decrypts task and configuration files for execution.

T1559
Inter-Process Communication
MalwareHyperStack

HyperStack can connect to the IPC$ share on remote machines.

T1573.001
Symmetric Cryptography
MalwareHyperStack

HyperStack has used RSA encryption for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCarbon

Carbon has used RSA encryption for C2 communications.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.