Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTomiris | Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration. |
| T1027.002 Software Packing |
MalwareTomiris | Tomiris has been packed with UPX. |
| T1041 Exfiltration Over C2 Channel |
MalwareTomiris | Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server. |
| T1053.005 Scheduled Task |
MalwareTomiris | Tomiris has used `SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00` to establish persistence. |
| T1071.001 Web Protocols |
MalwareTomiris | Tomiris can use HTTP to establish C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareTomiris | Tomiris can download files and execute them on a victim's system. |
| T1497.003 Time Based Checks |
MalwareTomiris | Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems. |
| T1568 Dynamic Resolution |
MalwareTomiris | Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.