TURNEDUP

S0199

Malware.View on attack.mitre.org

About this malware

TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1055.004
Asynchronous Procedure Call

TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection."

T1059.003
Windows Command Shell

TURNEDUP is capable of creating a reverse shell.

T1082
System Information Discovery

TURNEDUP is capable of gathering system information.

T1105
Ingress Tool Transfer

TURNEDUP is capable of downloading additional files.

T1113
Screen Capture

TURNEDUP is capable of taking screenshots.

T1547.001
Registry Run Keys / Startup Folder

TURNEDUP is capable of writing to a Registry Run key to establish.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT33 Sept 2017 Open source
    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.
  2. FireEye APT33 Webinar Sept 2017 Open source
    Davis, S. and Carr, N. (2017, September 21). APT33: New Insights into Iranian Cyber Espionage Group. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.