Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareCarbon | Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1071.001 Web Protocols |
MalwareCarbon | Carbon can use HTTP in C2 communications. |
| T1078.001 Default Accounts |
MalwareHyperStack | HyperStack can use default credentials to connect to IPC$ shares on remote machines. |
| T1087.001 Local Account |
MalwareHyperStack | HyperStack can enumerate all account names on a remote share. |
| T1090.001 Internal Proxy |
MalwareKazuar | Kazuar has used internal nodes on the compromised network for C2 communications. |
| T1102 Web Service |
MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| T1102 Web Service |
GroupTurla | Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications. |
| T1106 Native API |
MalwareHyperStack | HyperStack can use Windows API's |
| T1112 Modify Registry |
MalwareHyperStack | HyperStack can add the name of its communication pipe to |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCarbon | Carbon decrypts task and configuration files for execution. |
| T1559 Inter-Process Communication |
MalwareHyperStack | HyperStack can connect to the IPC$ share on remote machines. |
| T1573.001 Symmetric Cryptography |
MalwareHyperStack | HyperStack has used RSA encryption for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCarbon | Carbon has used RSA encryption for C2 communications. |
| T1584.004 Server |
GroupTurla | Turla has used compromised servers as infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.