Truvasys

Truvasys is first-stage malware that has been used by PROMETHIUM. It is a collection of modules written in the Delphi programming language. [1] [2] [3]

ID: S0178
Type: MALWARE
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1036 Masquerading To establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager.[1]
Enterprise T1060 Registry Run Keys / Startup Folder Truvasys adds a Registry Run key to establish persistence.[1]

Groups

Groups that use this software:

PROMETHIUM

References