Malware.View on attack.mitre.org
PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server. |
| T1057 Process Discovery |
PowerStallion has been used to monitor process lists. |
| T1059.001 PowerShell |
PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server. |
| T1070.006 Timestomp |
PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file. |
| T1102.002 Bidirectional Communication |
PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.