Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1027.015 Compression |
MalwareSocGholish | The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1057 Process Discovery |
MalwareSocGholish | SocGholish can list processes on targeted hosts. |
| T1059.007 JavaScript |
MalwareSocGholish | The SocGholish payload is executed as JavaScript. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1105 Ingress Tool Transfer |
MalwareSocGholish | SocGholish can download additional malware to infected hosts. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1518 Software Discovery |
MalwareSocGholish | SocGholish can identify the victim's browser in order to serve the correct fake update page. |
| T1584.001 Domains |
GroupMustard Tempest | Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1608.004 Drive-by Target |
GroupMustard Tempest | Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
| T1614 System Location Discovery |
MalwareSocGholish | SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.