QUIETCANARY

MITRE ATT&CK: S1076 View on attack.mitre.org

Aliases: Tunnus, Kapushka, QUIETCANARY

First seen
2022-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:06:13

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

QUIETCANARY is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.

Detection coverage

  • 88 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Hidden Window (attack-pattern)
  • Data Staged (attack-pattern)
  • Native API (attack-pattern)
  • Web Protocols (attack-pattern)
  • Query Registry (attack-pattern)
  • Standard Encoding (attack-pattern)

Used by threat actors

  • C0026 (campaign)

Reports & references

  • Kaspersky — 110355 (report)
  • Kaspersky — 109552 (report)
  • Mandiant — Turla Galaxy Opportunity (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Quietcanary (report)
  • MITRE ATT&CK — S1076 (report)

External references