ESET Research. (2018, May 22). Turla Mosquito: A shift towards more generic tools. Retrieved July 3, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
GroupTurla | Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1105 Ingress Tool Transfer |
GroupTurla | Turla has used shellcode to download Meterpreter after compromising a victim. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.