Malware.View on attack.mitre.org
HyperStack is a RPC-based backdoor used by Turla since at least 2018. HyperStack has similarities to other backdoors used by Turla including Carbon.
| Technique | Procedure example |
|---|---|
| T1078.001 Default Accounts |
HyperStack can use default credentials to connect to IPC$ shares on remote machines. |
| T1087.001 Local Account |
HyperStack can enumerate all account names on a remote share. |
| T1106 Native API |
HyperStack can use Windows API's |
| T1112 Modify Registry |
HyperStack can add the name of its communication pipe to |
| T1559 Inter-Process Communication |
HyperStack can connect to the IPC$ share on remote machines. |
| T1573.001 Symmetric Cryptography |
HyperStack has used RSA encryption for C2 communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.