Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCrutch | Crutch can exfiltrate files from compromised systems. |
| T1008 Fallback Channels |
MalwareCrutch | Crutch has used a hardcoded GitHub repository as a fallback channel. |
| T1020 Automated Exfiltration |
MalwareCrutch | Crutch has automatically exfiltrated stolen files to Dropbox. |
| T1025 Data from Removable Media |
MalwareCrutch | Crutch can monitor removable drives and exfiltrate files matching a given extension list. |
| T1036.004 Masquerade Task or Service |
MalwareCrutch | Crutch has established persistence with a scheduled task impersonating the Outlook item finder. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrutch | Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API). |
| T1053.005 Scheduled Task |
MalwareCrutch | Crutch has the ability to persist using scheduled tasks. |
| T1071.001 Web Protocols |
MalwareCrutch | Crutch has conducted C2 communications with a Dropbox account using the HTTP API. |
| T1074.001 Local Data Staging |
MalwareCrutch | Crutch has staged stolen files in the |
| T1078.003 Local Accounts |
GroupTurla | Turla has abused local accounts that have the same password across the victim’s network. |
| T1087.001 Local Account |
GroupTurla | Turla has used |
| T1102 Web Service |
GroupTurla | Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareCrutch | Crutch can use Dropbox to receive commands and upload stolen data. |
| T1119 Automated Collection |
MalwareCrutch | Crutch can automatically monitor removable drives in a loop and copy interesting files. |
| T1120 Peripheral Device Discovery |
MalwareCrutch | Crutch can monitor for removable drives being plugged into the compromised machine. |
| T1560.001 Archive via Utility |
MalwareCrutch | Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCrutch | Crutch has exfiltrated stolen data to Dropbox. |
| T1574.001 DLL |
MalwareCrutch | Crutch can persist via DLL search order hijacking on Google Chrome, Mozilla Firefox, or Microsoft OneDrive. |
| T1583.006 Web Services |
GroupTurla | Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.