Penquin

S0587

Malware.View on attack.mitre.org

About this malware

Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1016
System Network Configuration Discovery

Penquin can report the IP of the compromised host to attacker controlled infrastructure.

T1027.005
Indicator Removal from Tools

Penquin can remove strings from binaries.

T1027.013
Encrypted/Encoded File

Penquin has encrypted strings in the binary for obfuscation.

T1036.005
Match Legitimate Resource Name or Location

Penquin has mimicked the Cron binary to hide itself on compromised systems.

T1040
Network Sniffing

Penquin can sniff network traffic to look for packets matching specific conditions.

T1041
Exfiltration Over C2 Channel

Penquin can execute the command code do_upload to send files to C2.

T1053.003
Cron

Penquin can use Cron to create periodic and pre-scheduled background jobs.

T1059.004
Unix Shell

Penquin can execute remote commands using bash scripts.

T1070.004
File Deletion

Penquin can delete downloaded executables after running them.

T1082
System Information Discovery

Penquin can report the file system type of a compromised host to C2.

T1083
File and Directory Discovery

Penquin can use the command code do_vslist to send file names, size, and status to C2.

T1095
Non-Application Layer Protocol

The Penquin C2 mechanism is based on TCP and UDP packets.

T1105
Ingress Tool Transfer

Penquin can execute the command code do_download to retrieve remote files from C2.

T1205
Traffic Signaling

Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions.

T1205.002
Socket Filters

Penquin installs a `TCP` and `UDP` filter on the `eth0` interface.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Kaspersky Turla Penquin December 2014 Open source
    Baumgartner, K. and Raiu, C. (2014, December 8). The ‘Penquin’ Turla. Retrieved March 11, 2021.
  2. Leonardo Turla Penquin May 2020 Open source
    Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.