Tarrask
MITRE ATT&CK: S1011 View on attack.mitre.org
Aliases: Tarrask
- First seen
- 2021-08-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:35:01
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Tarrask is malware that has been used by HAFNIUM since at least August 2021. Tarrask was designed to evade digital defenses and maintain persistence by generating concealed scheduled tasks.
Detection coverage
- 170 Sigma rules
Malware & tools used
- Match Legitimate Resource Name or Location (attack-pattern)
- Windows Command Shell (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Scheduled Task (attack-pattern)
- Modify Registry (attack-pattern)
- Hide Artifacts (attack-pattern)
Used by threat actors
- HAFNIUM (threat-actor)
Reports & references
- Microsoft — Tarrask Malware Uses Scheduled Tasks For Defense Evasion (report)
- MITRE ATT&CK — S1011 (report)