Check out the results from our first round of ATT&CK Evaluations at attackevals.mitre.org!

Truvasys

Truvasys is first-stage malware that has been used by PROMETHIUM. It is a collection of modules written in the Delphi programming language. [1] [2] [3]

ID: S0178
Aliases: Truvasys
Type: MALWARE
Platforms: Windows

Version: 1.0

Alias Descriptions

NameDescription
Truvasys[1] [2] [3]

Techniques Used

DomainIDNameUse
EnterpriseT1036MasqueradingTo establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager.[1]
EnterpriseT1060Registry Run Keys / Startup FolderTruvasys adds a Registry Run key to establish persistence.[1]

Groups

Groups that use this software:

PROMETHIUM

References