ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9010×

36 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGlassWorm

GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads.

T1008
Fallback Channels
MalwareGlassWorm

GlassWorm has utilized Google Calendar as backup C2.

T1027.013
Encrypted/Encoded File
MalwareGlassWorm

GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field.

T1027.018
Invisible Unicode
MalwareGlassWorm

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1036
Masquerading
MalwareGlassWorm

GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects.

T1059.002
AppleScript
MalwareGlassWorm

GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1071.001
Web Protocols
MalwareGlassWorm

GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers.

T1074.001
Local Data Staging
MalwareGlassWorm

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1082
System Information Discovery
MalwareGlassWorm

GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts.

T1090.001
Internal Proxy
MalwareGlassWorm

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

T1102.001
Dead Drop Resolver
MalwareGlassWorm

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1105
Ingress Tool Transfer
MalwareGlassWorm

GlassWorm has downloaded additional payloads from C2.

T1124
System Time Discovery
MalwareGlassWorm

GlassWorm has the ability to check the system’s time zone on the victim device.

T1140
Deobfuscate/Decode Files or Information
MalwareGlassWorm

GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

T1213.003
Code Repositories
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

T1213.006
Databases
MalwareGlassWorm

GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`.

T1217
Browser Information Discovery
MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

T1480
Execution Guardrails
MalwareGlassWorm

GlassWorm has utilized logic to avoid executing on Russian based devices.

T1518
Software Discovery
MalwareGlassWorm

GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1547.001
Registry Run Keys / Startup Folder
MalwareGlassWorm

GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`.

T1554
Compromise Host Software Binary
MalwareGlassWorm

GlassWorm can modify hardware wallet applications.

T1555.001
Keychain
MalwareGlassWorm

GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`.

T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1560.001
Archive via Utility
MalwareGlassWorm

GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`.

T1564.003
Hidden Window
MalwareGlassWorm

GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions.

T1565.002
Transmitted Data Manipulation
MalwareGlassWorm

GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing.

T1571
Non-Standard Port
MalwareGlassWorm

GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability.

T1602.002
Network Device Configuration Dump
MalwareGlassWorm

GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`.

T1614
System Location Discovery
MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

T1614.001
System Language Discovery
MalwareGlassWorm

GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device.

T1657
Financial Theft
MalwareGlassWorm

GlassWorm has the ability to steal credentials for cryptocurrency wallets.

T1678
Delay Execution
MalwareGlassWorm

GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.