Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareGlassWorm | GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads. |
| T1008 Fallback Channels |
MalwareGlassWorm | GlassWorm has utilized Google Calendar as backup C2. |
| T1027.013 Encrypted/Encoded File |
MalwareGlassWorm | GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field. |
| T1027.018 Invisible Unicode |
MalwareGlassWorm | GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors. |
| T1036 Masquerading |
MalwareGlassWorm | GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects. |
| T1059.002 AppleScript |
MalwareGlassWorm | GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain. |
| T1059.007 JavaScript |
MalwareGlassWorm | GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript. |
| T1071.001 Web Protocols |
MalwareGlassWorm | GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers. |
| T1074.001 Local Data Staging |
MalwareGlassWorm | GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`. |
| T1082 System Information Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts. |
| T1090.001 Internal Proxy |
MalwareGlassWorm | GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1105 Ingress Tool Transfer |
MalwareGlassWorm | GlassWorm has downloaded additional payloads from C2. |
| T1124 System Time Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the system’s time zone on the victim device. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGlassWorm | GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareGlassWorm | GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github. |
| T1213.003 Code Repositories |
MalwareGlassWorm | GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`. |
| T1213.006 Databases |
MalwareGlassWorm | GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`. |
| T1217 Browser Information Discovery |
MalwareGlassWorm | GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets. |
| T1480 Execution Guardrails |
MalwareGlassWorm | GlassWorm has utilized logic to avoid executing on Russian based devices. |
| T1518 Software Discovery |
MalwareGlassWorm | GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite. |
| T1539 Steal Web Session Cookie |
MalwareGlassWorm | GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers. |
| T1543.001 Launch Agent |
MalwareGlassWorm | GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGlassWorm | GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`. |
| T1554 Compromise Host Software Binary |
MalwareGlassWorm | GlassWorm can modify hardware wallet applications. |
| T1555.001 Keychain |
MalwareGlassWorm | GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`. |
| T1555.003 Credentials from Web Browsers |
MalwareGlassWorm | GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers. |
| T1560.001 Archive via Utility |
MalwareGlassWorm | GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`. |
| T1564.003 Hidden Window |
MalwareGlassWorm | GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions. |
| T1565.002 Transmitted Data Manipulation |
MalwareGlassWorm | GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing. |
| T1571 Non-Standard Port |
MalwareGlassWorm | GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability. |
| T1602.002 Network Device Configuration Dump |
MalwareGlassWorm | GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`. |
| T1614 System Location Discovery |
MalwareGlassWorm | GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute. |
| T1614.001 System Language Discovery |
MalwareGlassWorm | GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device. |
| T1657 Financial Theft |
MalwareGlassWorm | GlassWorm has the ability to steal credentials for cryptocurrency wallets. |
| T1678 Delay Execution |
MalwareGlassWorm | GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.