Baumgartner, K. and Raiu, C. (2014, December 8). The ‘Penquin’ Turla. Retrieved March 11, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1040 Network Sniffing |
MalwarePenquin | Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1095 Non-Application Layer Protocol |
MalwarePenquin | The Penquin C2 mechanism is based on TCP and UDP packets. |
| T1205 Traffic Signaling |
MalwarePenquin | Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.