Penquin — Malware Profile
Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014.
MITRE ATT&CK techniques (18)
- T1016 System Network Configuration Discovery
- T1027.005 Indicator Removal from Tools
- T1027.013 Encrypted/Encoded File
- T1036.005 Match Legitimate Resource Name or Location
- T1040 Network Sniffing
- T1041 Exfiltration Over C2 Channel
- T1053.003 Cron
- T1059.004 Unix Shell
- T1070.004 File Deletion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1205 Traffic Signaling
- T1205.002 Socket Filters
- T1222.002 Linux and Mac Permissions
- T1573.002 Asymmetric Cryptography
- T1680 Local Storage Discovery