ATT&CKReferencesTarrask scheduled task

Tarrask scheduled task

Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareTarrask

Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections.

T1036.005
Match Legitimate Resource Name or Location
MalwareTarrask

Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`.

T1053.005
Scheduled Task
MalwareTarrask

Tarrask is able to create “hidden” scheduled tasks for persistence.

T1059.003
Windows Command Shell
MalwareTarrask

Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1112
Modify Registry
MalwareTarrask

Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks.

T1134.001
Token Impersonation/Theft
MalwareTarrask

Tarrask leverages token theft to obtain `lsass.exe` security permissions.

T1190
Exploit Public-Facing Application
GroupHAFNIUM

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1564
Hide Artifacts
MalwareTarrask

Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.