ATT&CKReferencesKaspersky Tomiris Sep 2021

Kaspersky Tomiris Sep 2021

Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTomiris

Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration.

T1027.002
Software Packing
MalwareTomiris

Tomiris has been packed with UPX.

T1041
Exfiltration Over C2 Channel
MalwareTomiris

Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server.

T1053.005
Scheduled Task
MalwareTomiris

Tomiris has used `SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00` to establish persistence.

T1071.001
Web Protocols
MalwareTomiris

Tomiris can use HTTP to establish C2 communications.

T1105
Ingress Tool Transfer
MalwareTomiris

Tomiris can download files and execute them on a victim's system.

T1497.003
Time Based Checks
MalwareTomiris

Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems.

T1568
Dynamic Resolution
MalwareTomiris

Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.