ATT&CKSoftwareHyperStack

HyperStack

S0537

Malware.View on attack.mitre.org

About this malware

HyperStack is a RPC-based backdoor used by Turla since at least 2018. HyperStack has similarities to other backdoors used by Turla including Carbon.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1078.001
Default Accounts

HyperStack can use default credentials to connect to IPC$ shares on remote machines.

T1087.001
Local Account

HyperStack can enumerate all account names on a remote share.

T1106
Native API

HyperStack can use Windows API's ConnectNamedPipe and WNetAddConnection2 to detect incoming connections and connect to remote shares.

T1112
Modify Registry

HyperStack can add the name of its communication pipe to HKLM\SYSTEM\\CurrentControlSet\\Services\\lanmanserver\\parameters\NullSessionPipes.

T1559
Inter-Process Communication

HyperStack can connect to the IPC$ share on remote machines.

T1573.001
Symmetric Cryptography

HyperStack has used RSA encryption for C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Accenture HyperStack October 2020 Open source
    Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.