ATT&CKSoftwareTrailBlazer

TrailBlazer

S0682

Malware.View on attack.mitre.org

About this malware

TrailBlazer is a modular malware that has been used by APT29 since at least 2019.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1001
Data Obfuscation

TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests.

T1001.001
Junk Data

TrailBlazer has used random identifier strings to obscure its C2 operations and result codes.

T1036
Masquerading

TrailBlazer has used filenames that match the name of the compromised system in attempt to avoid detection.

T1071.001
Web Protocols

TrailBlazer has used HTTP requests for C2.

T1546.003
Windows Management Instrumentation Event Subscription

TrailBlazer has the ability to use WMI for persistence.

Groups that use it1

Campaigns1

References1

  1. CrowdStrike StellarParticle January 2022 Open source
    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.