ATT&CKReferencesESET Turla Mosquito May 2018

ESET Turla Mosquito May 2018

ESET Research. (2018, May 22). Turla Mosquito: A shift towards more generic tools. Retrieved July 3, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
GroupTurla

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

T1059.001
PowerShell
GroupTurla

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1102.002
Bidirectional Communication
GroupTurla

A Turla JavaScript backdoor has used Google Apps Script as its C2 server.

T1105
Ingress Tool Transfer
GroupTurla

Turla has used shellcode to download Meterpreter after compromising a victim.

T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.