TURNEDUP
MITRE ATT&CK: S0199 View on attack.mitre.org
Aliases: Notestuk, TURNEDUP
- First seen
- 2017-02-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:45:26
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:sa country_code:us
Context
TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.
Detection coverage
- 1 YARA rules
- 168 Sigma rules
Malware & tools used
- Asynchronous Procedure Call (attack-pattern)
- Screen Capture (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
Used by threat actors
- APT33 (threat-actor)
Detection rules
- MALPEDIA_Win_Turnedup_Auto (yara-rule)
Reports & references
- Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
- brighttalk.com — 275683 (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Turnedup (report)
- cyberbit.com — New Early Bird Code Injection Technique Discovered (report)
- cyberbit.com — New Early Bird Code Injection Technique Discovered (report)
- MITRE ATT&CK — S0199 (report)