Truvasys

Truvasys is first-stage malware that has been used by PROMETHIUM. It is a collection of modules written in the Delphi programming language. [1] [2] [3]

ID: S0178
Type: MALWARE
Platforms: Windows

Version: 1.0

Techniques Used

DomainIDNameUse
EnterpriseT1036MasqueradingTo establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager.[1]
EnterpriseT1060Registry Run Keys / Startup FolderTruvasys adds a Registry Run key to establish persistence.[1]

Groups

Groups that use this software:

PROMETHIUM

References