ATT&CKReferencesESET Turla Lunar toolset May 2024

ESET Turla Lunar toolset May 2024

Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples55

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

T1001.002
Steganography
MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

T1016
System Network Configuration Discovery
MalwareLunarWeb

LunarWeb can use shell commands to discover network adapters and configuration.

T1016
System Network Configuration Discovery
MalwareLunarLoader

LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key.

T1027.013
Encrypted/Encoded File
MalwareLunarMail

LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively.

T1027.013
Encrypted/Encoded File
MalwareLunarWeb

The LunarWeb install files have been encrypted with AES-256.

T1030
Data Transfer Size Limits
MalwareLunarWeb

LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB.

T1033
System Owner/User Discovery
MalwareLunarWeb

LunarWeb can collect user information from the targeted host.

T1036.005
Match Legitimate Resource Name or Location
GroupTurla

Turla has named components of LunarWeb to mimic Zabbix agent logs.

T1041
Exfiltration Over C2 Channel
MalwareLunarMail

LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration.

T1047
Windows Management Instrumentation
MalwareLunarWeb

LunarWeb can use WMI queries for discovery on the victim host.

T1049
System Network Connections Discovery
MalwareLunarWeb

LunarWeb can enumerate system network connections.

T1057
Process Discovery
MalwareLunarWeb

LunarWeb has used shell commands to list running processes.

T1059.001
PowerShell
MalwareLunarWeb

LunarWeb has the ability to run shell commands via PowerShell.

T1059.003
Windows Command Shell
MalwareLunarWeb

LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<⁠random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output.

T1059.005
Visual Basic
MalwareLunarMail

LunarMail has been installed using a VBA macro.

T1069.001
Local Groups
MalwareLunarWeb

LunarWeb can discover local group memberships.

T1070.004
File Deletion
MalwareLunarMail

LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one.

T1070.004
File Deletion
MalwareLunarWeb

LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail.

T1070.008
Clear Mailbox Data
MalwareLunarMail

LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration.

T1071.001
Web Protocols
MalwareLunarWeb

LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands.

T1071.003
Mail Protocols
MalwareLunarMail

LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI).

T1074.001
Local Data Staging
MalwareLunarMail

LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration.

T1082
System Information Discovery
MalwareLunarMail

LunarMail can capture environmental variables on compromised hosts.

T1082
System Information Discovery
MalwareLunarWeb

LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system.

T1083
File and Directory Discovery
MalwareLunarMail

LunarMail can search its staging directory for output files it has produced.

T1083
File and Directory Discovery
MalwareLunarWeb

LunarWeb has the ability to retrieve directory listings.

T1090
Proxy
MalwareLunarWeb

LunarWeb has the ability to use a HTTP proxy server for C&C communications.

T1095
Non-Application Layer Protocol
MalwareLunarMail

LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain.

T1104
Multi-Stage Channels
MalwareLunarWeb

LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands.

T1113
Screen Capture
MalwareLunarMail

LunarMail can capture screenshots from compromised hosts.

T1114.001
Local Email Collection
MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

T1132.001
Standard Encoding
MalwareLunarWeb

LunarWeb can use Base64 encoding to obfuscate C2 commands.

T1135
Network Share Discovery
MalwareLunarWeb

LunarWeb can identify shared resources in compromised environments.

T1137.006
Add-ins
MalwareLunarMail

LunarMail has the ability to use Outlook add-ins for persistence.

T1137.006
Add-ins
MalwareLunarLoader

LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarLoader

LunarLoader can deobfuscate files containing the next stages in the infection chain.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarWeb

LunarWeb can decrypt strings related to communication configuration using RC4 with a static key.

T1140
Deobfuscate/Decode Files or Information
MalwareLunarMail

LunarMail can decrypt strings to retrieve configuration settings.

T1204.002
Malicious File
MalwareLunarMail

LunarMail has been installed through a malicious macro in a Microsoft Word document.

T1480
Execution Guardrails
MalwareLunarLoader

LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets.

T1497.003
Time Based Checks
MalwareLunarWeb

LunarWeb can pause for a number of hours before entering its C2 communication loop.

T1518
Software Discovery
MalwareLunarWeb

LunarWeb can list installed software on compromised systems.

T1518.001
Security Software Discovery
MalwareLunarWeb

LunarWeb has run shell commands to obtain a list of installed security products.

T1543
Create or Modify System Process
MalwareLunarMail

LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory.

T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

T1559
Inter-Process Communication
MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

T1560.001
Archive via Utility
MalwareLunarWeb

LunarWeb can create a ZIP archive with specified files and directories.

T1560.002
Archive via Library
MalwareLunarWeb

LunarWeb can zlib-compress data prior to exfiltration.

T1564.012
File/Path Exclusions
GroupTurla

Turla has placed LunarWeb install files into directories that are excluded from scanning.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.