IronNetInjector — Malware Profile
IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
MITRE ATT&CK techniques (8)
- T1027.013 Encrypted/Encoded File
- T1036.004 Masquerade Task or Service
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1055.001 Dynamic-link Library Injection
- T1057 Process Discovery
- T1059.006 Python
- T1140 Deobfuscate/Decode Files or Information