Description
[Carbon](https://attack.mitre.org/software/S0335) is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims. [Carbon](https://attack.mitre.org/software/S0335) has been selectively used by [Turla](https://attack.mitre.org/groups/G0010) to target government and foreign affairs-related organizations in Central Asia.(Citation: ESET Carbon Mar 2017)(Citation: Securelist Turla Oct 2018)
External References
Techniques Used by This Malware
- T1012 — Query Registry
- T1016 — System Network Configuration Discovery
- T1018 — Remote System Discovery
- T1027 — Obfuscated Files or Information
- T1048.003 — Exfiltration Over Unencrypted Non-C2 Protocol
- T1049 — System Network Connections Discovery
- T1053.005 — Scheduled Task
- T1055.001 — Dynamic-link Library Injection
- T1057 — Process Discovery
- T1069 — Permission Groups Discovery
- T1071.001 — Web Protocols
- T1074.001 — Local Data Staging
- T1095 — Non-Application Layer Protocol
- T1102 — Web Service
- T1124 — System Time Discovery
- T1140 — Deobfuscate/Decode Files or Information
- T1543.003 — Windows Service
- T1573.002 — Asymmetric Cryptography