Tarrask

MITRE ATT&CK: S1011 View on attack.mitre.org

Aliases: Tarrask

First seen
2021-08-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:35:01

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Tarrask is malware that has been used by HAFNIUM since at least August 2021. Tarrask was designed to evade digital defenses and maintain persistence by generating concealed scheduled tasks.

Detection coverage

  • 170 Sigma rules

Malware & tools used

  • Match Legitimate Resource Name or Location (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Modify Registry (attack-pattern)
  • Hide Artifacts (attack-pattern)

Used by threat actors

Reports & references

  • Microsoft — Tarrask Malware Uses Scheduled Tasks For Defense Evasion (report)
  • MITRE ATT&CK — S1011 (report)

External references