Tarrask is a Windows persistence and defense-evasion malware/tool publicly named by Microsoft Threat Intelligence Center (MSTIC). It is associated with the China-linked HAFNIUM threat actor. MSTIC reported HAFNIUM activity using Tarrask against organizations including telecommunications, internet service provider, and data services entities, and also described HAFNIUM as targeting U.S. organizations across sectors such as infectious disease research, law firms, higher education, defense contractors, think tanks, and NGOs. In reported intrusions, HAFNIUM commonly gained access by exploiting vulnerabilities in internet-facing servers, including Exchange Server zero-days, and then deployed web shells and other malware.
Tarrask maintains persistence on compromised Windows systems by creating scheduled tasks and then hiding them. It creates task-related registry entries under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree<TASK_NAME> and HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{GUID}. It then deletes the Security Descriptor (SD) value/subkey from the TaskCache\Tree path, causing the scheduled task to disappear from Windows Task Scheduler and from the schtasks command-line utility while remaining present in the registry. The hidden task can still be identified through manual registry inspection. Microsoft reported an observed task named "WinUpdate" that was used to re-establish dropped command-and-control connections.
The content also states that deleting the SD value normally returns Access Denied unless performed in the SYSTEM context, and that Tarrask leverages token theft to obtain lsass.exe security permissions in order to carry out this action. Tarrask has masqueraded as executable names including winupdate.exe, date.exe, and win.exe. High-confidence detection opportunities mentioned in the content include monitoring for deletion of SD values under the Schedule\TaskCache\Tree registry path, especially by the SYSTEM user, and hunting for hidden scheduled tasks missing SD values.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft Threat Intelligence Center (MSTIC) highlighted the simplicity of the technique employed by the Tarrask malware that creates “hidden” scheduled tasks on the system to maintain persistence.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
Bisonal has deleted Registry keys to clean up its prior activity ... FIN8 has deleted Registry keys during post compromise cleanup activities ... SUNBURST ... deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as using scheduled-task hiding via deletion of the Task 'SD' registry value/key (defense evasion).
Tarrask is malware referenced in connection with using scheduled tasks for defense evasion, specifically by deleting or hiding scheduled task security descriptors in the registry to conceal persistence.
A Windows persistence malware/tool used to create hidden scheduled tasks by manipulating Task Scheduler registry keys and deleting the Security Descriptor (SD) value so tasks are hidden from Task Scheduler and schtasks. It also used token theft to obtain SYSTEM-level permissions associated with lsass.exe to delete the SD value and re-establish dropped C2 connections.
A Windows persistence and defense evasion malware used to create hidden scheduled tasks by deleting the Security Descriptor value from the TaskCache\Tree registry path, causing the task to disappear from Task Scheduler and schtasks while maintaining access and re-establishing C2 connectivity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.