Malware.View on attack.mitre.org
HAMMERTOSS is a backdoor that was used by APT29 in 2015.
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
HAMMERTOSS is controlled via commands that are appended to image files. |
| T1059.001 PowerShell |
HAMMERTOSS is known to use PowerShell. |
| T1071.001 Web Protocols |
The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands. |
| T1102.003 One-Way Communication |
The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day. |
| T1564.003 Hidden Window |
HAMMERTOSS has used |
| T1567.002 Exfiltration to Cloud Storage |
HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| T1573.001 Symmetric Cryptography |
Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.