HyperStack is a custom RPC-based backdoor used by Turla, first observed in 2018 and assessed with high confidence to be part of Turla’s long-running state-sponsored espionage operations against government organizations and embassies. In the referenced intrusion against a European government organization, Turla used HyperStack alongside Kazuar and Carbon to maintain overlapping access, execute commands, exfiltrate data, support lateral movement, and preserve persistence.
HyperStack uses named pipes to execute remote procedure calls from a controller to an infected device. Updated samples observed in 2020 showed functionality resembling Turla’s previously disclosed RPC backdoors and the Carbon backdoor. The malware attempts lateral movement by connecting to remote systems’ IPC$ shares using a null session or default credentials; if successful, it can forward RPC commands to the remote device and likely copy itself there. A simpler variant observed in the same campaign allowed operators to run commands via a named pipe without IPC$ enumeration.
For persistence and privilege, HyperStack copies itself to C:\ADSchemeIntegrity.exe and installs itself as the service "Active Directory Scheme Integrity Service" with SYSTEM-level privileges. It modifies HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters\NullSessionPipes to add the named pipe adschemerpc, sets the named pipe security descriptor to S:(ML;;NW;;;S-1-16-0) to make the pipe anonymously accessible, and sets HKLM\SYSTEM\CurrentControlSet\Control\LSA\Restrict Anonymous to 0 to allow anonymous enumeration of account names and shared resources. It uses a custom named-pipe handshake, checking for B19B055CA11CACA0 and responding with CACA05ACCE55F11E.
HyperStack writes a configuration file to %SystemRoot%\INF\backport.inf containing keys including Type, CLSID, PRVK, Revision, and Signature; the Type value is set to SilentMoon, and the malware generates an RSA PKCS key using CryptGenKey for session key encryption. It writes command results and error messages to randomly named log files in %Temp% using the prefixes sm and ~D, and deletes files with the prefix ~X. Reported related filenames include ADSchemeIntegrity.exe and hyperstack.exe.
Separate reporting also noted that Turla used an RPC backdoor variant as a payload delivered by obfuscated IronPython-based BYOI tooling dubbed IronNetInjector. In that activity, encrypted payloads were decrypted with Base64 and Rijndael and reflectively injected via a .NET injector. The content does not provide enough detail to confirm whether that payload was HyperStack specifically.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HyperStack, first observed in 2018, is one of several RPC backdoors Turla uses. A sample identified in September 2020 has updated functionality which appears to be inspired the RPC backdoors previously publicly disclosed by ESET and Symantec Researchers as well as with the Carbon backdoor.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor payload variant embedded in some IronNetInjector IronPython scripts and loaded via the embedded .NET injector.
Turla RPC-based backdoor family referenced as a legacy/custom tool whose code and behaviors influenced HyperStack, including registry checks, named-pipe access, and lateral movement functionality.
Custom backdoor delivered via PowerShell scripts, used for remote access and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.