TinyTurla

S0668

Malware.View on attack.mitre.org

About this malware

TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

TinyTurla can upload files from a compromised host.

T1008
Fallback Channels

TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds.

T1012
Query Registry

TinyTurla can query the Registry for its configuration information.

T1027.011
Fileless Storage

TinyTurla can save its configuration parameters in the Registry.

T1029
Scheduled Transfer

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.

T1036.004
Masquerade Task or Service

TinyTurla has mimicked an existing Windows service by being installed as Windows Time Service.

T1036.005
Match Legitimate Resource Name or Location

TinyTurla has been deployed as `w64time.dll` to appear legitimate.

T1059.003
Windows Command Shell

TinyTurla has been installed using a .bat file.

T1071.001
Web Protocols

TinyTurla can use HTTPS in C2 communications.

T1105
Ingress Tool Transfer

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.

T1106
Native API

TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions.

T1112
Modify Registry

TinyTurla can set its configuration parameters in the Registry.

T1569.002
Service Execution

TinyTurla can install itself as a service on compromised machines.

T1573.002
Asymmetric Cryptography

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Talos TinyTurla September 2021 Open source
    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.