TURNEDUP

MITRE ATT&CK: S0199 View on attack.mitre.org

Aliases: Notestuk, TURNEDUP

First seen
2017-02-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:45:26

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:sa country_code:us

Context

TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.

Detection coverage

  • 1 YARA rules
  • 168 Sigma rules

Malware & tools used

  • Asynchronous Procedure Call (attack-pattern)
  • Screen Capture (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Turnedup_Auto (yara-rule)

Reports & references

  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • brighttalk.com — 275683 (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Turnedup (report)
  • cyberbit.com — New Early Bird Code Injection Technique Discovered (report)
  • cyberbit.com — New Early Bird Code Injection Technique Discovered (report)
  • MITRE ATT&CK — S0199 (report)

External references