ATT&CKReferencesESET Crutch December 2020

ESET Crutch December 2020

Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCrutch

Crutch can exfiltrate files from compromised systems.

T1008
Fallback Channels
MalwareCrutch

Crutch has used a hardcoded GitHub repository as a fallback channel.

T1020
Automated Exfiltration
MalwareCrutch

Crutch has automatically exfiltrated stolen files to Dropbox.

T1025
Data from Removable Media
MalwareCrutch

Crutch can monitor removable drives and exfiltrate files matching a given extension list.

T1036.004
Masquerade Task or Service
MalwareCrutch

Crutch has established persistence with a scheduled task impersonating the Outlook item finder.

T1041
Exfiltration Over C2 Channel
MalwareCrutch

Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API).

T1053.005
Scheduled Task
MalwareCrutch

Crutch has the ability to persist using scheduled tasks.

T1071.001
Web Protocols
MalwareCrutch

Crutch has conducted C2 communications with a Dropbox account using the HTTP API.

T1074.001
Local Data Staging
MalwareCrutch

Crutch has staged stolen files in the C:\AMD\Temp directory.

T1078.003
Local Accounts
GroupTurla

Turla has abused local accounts that have the same password across the victim’s network.

T1087.001
Local Account
GroupTurla

Turla has used net user to enumerate local accounts on the system.

T1102
Web Service
GroupTurla

Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications.

T1102.002
Bidirectional Communication
MalwareCrutch

Crutch can use Dropbox to receive commands and upload stolen data.

T1119
Automated Collection
MalwareCrutch

Crutch can automatically monitor removable drives in a loop and copy interesting files.

T1120
Peripheral Device Discovery
MalwareCrutch

Crutch can monitor for removable drives being plugged into the compromised machine.

T1560.001
Archive via Utility
MalwareCrutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.

T1567.002
Exfiltration to Cloud Storage
MalwareCrutch

Crutch has exfiltrated stolen data to Dropbox.

T1574.001
DLL
MalwareCrutch

Crutch can persist via DLL search order hijacking on Google Chrome, Mozilla Firefox, or Microsoft OneDrive.

T1583.006
Web Services
GroupTurla

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.