Mosquito

S0256

Malware.View on attack.mitre.org

About this malware

Mosquito is a Win32 backdoor that has been used by Turla. Mosquito is made up of three parts: the installer, the launcher, and the backdoor. The main backdoor is called CommanderDLL and is launched by the loader program.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1016
System Network Configuration Discovery

Mosquito uses the ipconfig command.

T1027.011
Fileless Storage

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

T1027.013
Encrypted/Encoded File

Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer.

T1033
System Owner/User Discovery

Mosquito runs whoami on the victim’s machine.

T1047
Windows Management Instrumentation

Mosquito's installer uses WMI to search for antivirus display names.

T1057
Process Discovery

Mosquito runs tasklist to obtain running processes.

T1059.001
PowerShell

Mosquito can launch PowerShell Scripts.

T1059.003
Windows Command Shell

Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server.

T1070.004
File Deletion

Mosquito deletes files using DeleteFileW API call.

T1105
Ingress Tool Transfer

Mosquito can upload and download files to the victim.

T1106
Native API

Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions.

T1112
Modify Registry

Mosquito can modify Registry keys under HKCU\Software\Microsoft\[dllname] to store configuration values. Mosquito also modifies Registry keys under HKCR\CLSID\...\InprocServer32 with a path to the launcher.

T1218.011
Rundll32

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1518.001
Security Software Discovery

Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system.

T1546.015
Component Object Model Hijacking

Mosquito uses COM hijacking as a method of persistence.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Turla Mosquito Jan 2018 Open source
    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.