Malware.View on attack.mitre.org
Truvasys is first-stage malware that has been used by PROMETHIUM. It is a collection of modules written in the Delphi programming language.
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
To establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager. |
| T1547.001 Registry Run Keys / Startup Folder |
Truvasys adds a Registry Run key to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.