Executive Summary
HyperStack is a sophisticated RPC‑based backdoor used by Turla that provides remote command execution, file transfer, and covert data exfiltration. Its design mirrors other Turla families like Carbon, emphasizing stealthy persistence and encrypted communications. The malware’s long‑term presence poses significant risks for targeted organizations seeking to maintain undetected access.
Enhanced Description
HyperStack is a modular RPC‑based backdoor that has been employed by the Turla threat group for several years, first documented in 2018 and referenced as early as October 2020 by Accenture. The malware leverages Remote Procedure Call (RPC) infrastructure to establish an authenticated channel between the compromised host and the attacker’s command‐and‐control (C2) server, allowing a wide range of administrative operations without visible network traffic. HyperStack shares architectural similarities with other Turla backdoors such as Carbon, indicating that it inherits design principles like dynamic module loading, encrypted communication, and stealthy persistence mechanisms. Once installed, HyperStack offers a comprehensive set of features typical for advanced persistent threats: remote execution of arbitrary commands, file upload/download, registry manipulation, process enumeration, memory dumping, and lateral movement via RPC or SMB. It also supports covert exfiltration channels by encapsulating data within encrypted payloads, thereby masking its activity from traditional signature‑based detection tools. The use of RPC not only obfuscates network traffic but also exploits legitimate Windows services, reducing the likelihood of triggering endpoint security alerts. From an operational standpoint, HyperStack serves as a critical component of Turla’s multi‑stage intrusion framework. By combining persistence, privileged execution, and advanced data exfiltration capabilities, it enables long‑term access to target networks, facilitating strategic espionage objectives such as credential theft, network reconnaissance, and the compromise of other endpoints.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the core functional description due to credible reporting from Accenture; however, detailed technical specifics (e.g., encryption methods, exact persistence mechanisms) are not fully documented, leaving gaps in understanding of full capabilities and mitigations.
HyperStack is a RPC-based backdoor used by Turla since at least 2018. HyperStack has similarities to other backdoors used by Turla including Carbon.(Citation: Accenture HyperStack October 2020)