TDTESS

S0164

Malware.View on attack.mitre.org

About this malware

TDTESS is a 64-bit .NET binary backdoor used by CopyKittens.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.003
Windows Command Shell

TDTESS provides a reverse shell on the victim.

T1070.004
File Deletion

TDTESS creates then deletes log files during installation of itself as a service.

T1070.006
Timestomp

After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file.

T1105
Ingress Tool Transfer

TDTESS has a command to download and execute an additional file.

T1543.003
Windows Service

If running as administrator, TDTESS installs itself as a new service named bmwappushservice to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ClearSky Wilted Tulip July 2017 Open source
    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.