During C0026, the threat actors collected documents from compromised hosts.2
campaign
C0026 C0026
- First seen
- August 2022
- Last seen
- September 2022
- Created
- 15 May 2023
- Last modified
- 31 July 2026
C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains. Several tools and tactics used during C0026 were consistent with historic Turla operations.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0026
During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.3
During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.4
During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.5
During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.6
For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.7
Standing C0026
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
13th percentile · 87% of 56 ATT&CK campaigns have more Enterprise techniques.
16th percentile · 84% of 56 ATT&CK campaigns have more tactics spanned.
88th percentile · 88% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
54th percentile · 54% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0026
179 distinct rules cover the 6 techniques recorded for this campaign. The 182 technique-to-rule mappings resolve to 179 distinct rules, because one rule can cover several techniques. 121 Sigma · 58 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org