ATT&CKSoftwareQUIETCANARY

QUIETCANARY

S1076

Malware.View on attack.mitre.org

About this malware

QUIETCANARY is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1012
Query Registry

QUIETCANARY has the ability to retrieve information from the Registry.

T1016
System Network Configuration Discovery

QUIETCANARY can identify the default proxy setting on a compromised host.

T1071.001
Web Protocols

QUIETCANARY can use HTTPS for C2 communications.

T1074
Data Staged

QUIETCANARY has the ability to stage data prior to exfiltration.

T1106
Native API

QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer.

T1132.001
Standard Encoding

QUIETCANARY can base64 encode C2 communications.

T1140
Deobfuscate/Decode Files or Information

QUIETCANARY can use a custom parsing routine to decode the command codes and additional parameters from the C2 before executing them.

T1564.003
Hidden Window

QUIETCANARY can execute processes in a hidden window.

T1573.001
Symmetric Cryptography

QUIETCANARY can RC4 encrypt C2 communications.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Suspected Turla Campaign February 2023 Open source
    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.