ATT&CKSoftwareHAMMERTOSS

HAMMERTOSS

S0037

Malware.View on attack.mitre.org

About this malware

HAMMERTOSS is a backdoor that was used by APT29 in 2015.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1001.002
Steganography

HAMMERTOSS is controlled via commands that are appended to image files.

T1059.001
PowerShell

HAMMERTOSS is known to use PowerShell.

T1071.001
Web Protocols

The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands.

T1102.003
One-Way Communication

The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day.

T1564.003
Hidden Window

HAMMERTOSS has used -WindowStyle hidden to conceal PowerShell windows.

T1567.002
Exfiltration to Cloud Storage

HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.

T1573.001
Symmetric Cryptography

Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command.

Groups that use it1

Campaigns0

None recorded.

References2

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.
  2. FireEye APT29 Open source
    FireEye Labs. (2015, July). HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Group. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.