Symantec DeepSight Adversary Intelligence Team. (2019, June 20). Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments. Retrieved July 8, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1025 Data from Removable Media |
GroupTurla | Turla RPC backdoors can collect files from USB thumb drives. |
| T1027.011 Fileless Storage |
GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1059.003 Windows Command Shell |
GroupTurla | Turla RPC backdoors have used cmd.exe to execute commands. |
| T1059.005 Visual Basic |
GroupTurla | Turla has used VBS scripts throughout its operations. |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1555.004 Windows Credential Manager |
GroupTurla | Turla has gathered credentials from the Windows Credential Manager tool. |
| T1560.001 Archive via Utility |
GroupTurla | Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1588.002 Tool |
GroupTurla | Turla has obtained and customized publicly-available tools like Mimikatz. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.