Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware HyperStack

HyperStack

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

HyperStack is a sophisticated RPC‑based backdoor used by Turla that provides remote command execution, file transfer, and covert data exfiltration. Its design mirrors other Turla families like Carbon, emphasizing stealthy persistence and encrypted communications. The malware’s long‑term presence poses significant risks for targeted organizations seeking to maintain undetected access.

Enhanced Description

HyperStack is a modular RPC‑based backdoor that has been employed by the Turla threat group for several years, first documented in 2018 and referenced as early as October 2020 by Accenture. The malware leverages Remote Procedure Call (RPC) infrastructure to establish an authenticated channel between the compromised host and the attacker’s command‐and‐control (C2) server, allowing a wide range of administrative operations without visible network traffic. HyperStack shares architectural similarities with other Turla backdoors such as Carbon, indicating that it inherits design principles like dynamic module loading, encrypted communication, and stealthy persistence mechanisms. Once installed, HyperStack offers a comprehensive set of features typical for advanced persistent threats: remote execution of arbitrary commands, file upload/download, registry manipulation, process enumeration, memory dumping, and lateral movement via RPC or SMB. It also supports covert exfiltration channels by encapsulating data within encrypted payloads, thereby masking its activity from traditional signature‑based detection tools. The use of RPC not only obfuscates network traffic but also exploits legitimate Windows services, reducing the likelihood of triggering endpoint security alerts. From an operational standpoint, HyperStack serves as a critical component of Turla’s multi‑stage intrusion framework. By combining persistence, privileged execution, and advanced data exfiltration capabilities, it enables long‑term access to target networks, facilitating strategic espionage objectives such as credential theft, network reconnaissance, and the compromise of other endpoints.

Key Capabilities

  • Establishes authenticated RPC communication with C2
  • Executes arbitrary commands remotely
  • Uploads and downloads files via encrypted channels
  • Manipulates the Windows registry for persistence
  • Enumerates processes and performs memory dumps
  • Facilitates lateral movement through SMB/RPC paths
  • Encodes exfiltrated data to evade detection

ATT&CK Techniques

T1059
T1071.001
T1047
T1003
T1105

Recommended Actions

  • Monitor outbound traffic for unusual RPC or WMI calls, especially on non‑standard ports
  • Implement strict egress filtering for encrypted payloads
  • Deploy EDR solutions that detect anomalous DLL imports and module loading
  • Block application of unknown certificates often used by Turla C2 servers
  • Conduct regular system integrity checks for persistence mechanisms such as scheduled tasks, services, or startup registry keys
  • Educate users to recognize phishing attempts that may deliver HyperStack
  • Update Windows RPC and WMI components to latest security patches

Suggested Tags

turla
backdoor
rpc
windows
persistent

Confidence Assessment

Moderate confidence in the core functional description due to credible reporting from Accenture; however, detailed technical specifics (e.g., encryption methods, exact persistence mechanisms) are not fully documented, leaving gaps in understanding of full capabilities and mitigations.

Description

HyperStack is a RPC-based backdoor used by Turla since at least 2018. HyperStack has similarities to other backdoors used by Turla including Carbon.(Citation: Accenture HyperStack October 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.