TURNEDUP

TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware. [1] [2]

ID: S0199
Type: MALWARE
Platforms: Windows
Contributors: Christiaan Beek, @ChristiaanBeek; Ryan Becwar
Version: 1.1
Created: 18 April 2018
Last Modified: 09 February 2021

Techniques Used

Domain ID Name Use
Enterprise T1547 .001 启动或登录自动启动执行: Registry Run Keys / Startup Folder

TURNEDUP is capable of writing to a Registry Run key to establish.[3]

Enterprise T1059 .003 命令与脚本解释器: Windows Command Shell

TURNEDUP is capable of creating a reverse shell.[1]

Enterprise T1113 屏幕捕获

TURNEDUP is capable of taking screenshots.[1]

Enterprise T1082 系统信息发现

TURNEDUP is capable of gathering system information.[1]

Enterprise T1105 输入工具传输

TURNEDUP is capable of downloading additional files.[1]

Enterprise T1055 .004 进程注入: Asynchronous Procedure Call

TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection."[3]

Groups That Use This Software

ID Name References
G0064 APT33

[1][2][4]

References