Uroburos

S0022

Malware.View on attack.mitre.org

About this malware

Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB) associated with the Turla toolset to collect intelligence on sensitive targets worldwide. Uroburos has several variants and has undergone nearly constant upgrade since its initial development in 2003 to keep it viable after public disclosures. Uroburos is typically deployed to external-facing nodes on a targeted network and has the ability to leverage additional tools and TTPs to further exploit an internal network. Uroburos has interoperable implants for Windows, Linux, and macOS, employs a high level of stealth in communications and architecture, and can easily incorporate new or replacement components.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1001.001
Junk Data

Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests.

T1001.003
Protocol or Service Impersonation

Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic.

T1005
Data from Local System

Uroburos can use its `Get` command to exfiltrate specified files from the compromised system.

T1008
Fallback Channels

Uroburos can use up to 10 channels to communicate between implants.

T1012
Query Registry

Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader.

T1014
Rootkit

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

T1027.002
Software Packing

Uroburos uses a custom packer.

T1027.009
Embedded Payloads

The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation.

T1027.011
Fileless Storage

Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.`

T1027.013
Encrypted/Encoded File

Uroburos can use AES and CAST-128 encryption to obfuscate resources.

T1036.004
Masquerade Task or Service

Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service.

T1055.001
Dynamic-link Library Injection

Uroburos can use DLL injection to load embedded files and modules.

T1057
Process Discovery

Uroburos can use its `Process List` command to enumerate processes on compromised hosts.

T1059.003
Windows Command Shell

Uroburos has the ability to use the command line for execution on the targeted system.

T1070.004
File Deletion

Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs.

View all 36 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023 Open source
    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.
  2. Kaspersky Turla Open source
    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.