Description
[Torisma](https://attack.mitre.org/software/S0678) is a second stage implant designed for specialized monitoring that has been used by [Lazarus Group](https://attack.mitre.org/groups/G0032). [Torisma](https://attack.mitre.org/software/S0678) was discovered during an investigation into the 2020 Operation North Star campaign that targeted the defense sector.(Citation: McAfee Lazarus Nov 2020)
External References
Techniques Used by This Malware
- T1016 — System Network Configuration Discovery
- T1027.002 — Software Packing
- T1027.013 — Encrypted/Encoded File
- T1041 — Exfiltration Over C2 Channel
- T1049 — System Network Connections Discovery
- T1071.001 — Web Protocols
- T1082 — System Information Discovery
- T1106 — Native API
- T1124 — System Time Discovery
- T1132.001 — Standard Encoding
- T1140 — Deobfuscate/Decode Files or Information
- T1480 — Execution Guardrails
- T1573.001 — Symmetric Cryptography