T1005 Data from Local System |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from local systems. |
T1016 System Network Configuration Discovery |
MalwareXORIndex Loader |
XORIndex Loader has leveraged webservices to identify the public IP of the victim host. |
T1027.010 Command Obfuscation |
MalwareXORIndex Loader |
XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder. |
T1027.013 Encrypted/Encoded File |
MalwareXORIndex Loader |
XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
T1033 System Owner/User Discovery |
MalwareXORIndex Loader |
XORIndex Loader has collected the username from the victim host. |
T1036.005 Match Legitimate Resource Name or Location |
MalwareXORIndex Loader |
XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads. |
T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1041 Exfiltration Over C2 Channel |
MalwareXORIndex Loader |
XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
T1059.007 JavaScript |
MalwareXORIndex Loader |
XORIndex Loader has executed malicious JavaScript code. |
T1070.004 File Deletion |
MalwareBeaverTail |
BeaverTail has deleted files from a compromised host after they were exfiltrated. |
T1070.004 File Deletion |
GroupContagious Interview |
Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration. |
T1071.001 Web Protocols |
MalwareXORIndex Loader |
XORIndex Loader has used HTTPS POST to communicate with C2. |
T1071.001 Web Protocols |
MalwareHexEval Loader |
HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
T1071.001 Web Protocols |
MalwareBeaverTail |
BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
T1074.001 Local Data Staging |
MalwareBeaverTail |
BeaverTail has staged collected data to the system’s temporary directory. |
T1082 System Information Discovery |
MalwareXORIndex Loader |
XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host. |
T1083 File and Directory Discovery |
MalwareBeaverTail |
BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1105 Ingress Tool Transfer |
MalwareXORIndex Loader |
XORIndex Loader has been used to download a malicious payload to include BeaverTail. |
T1105 Ingress Tool Transfer |
MalwareHexEval Loader |
HexEval Loader has been used to download a malicious payload to include BeaverTail. |
T1140 Deobfuscate/Decode Files or Information |
MalwareHexEval Loader |
HexEval Loader has decoded its payload prior to execution. |
T1140 Deobfuscate/Decode Files or Information |
MalwareXORIndex Loader |
XORIndex Loader can decode its payload prior to execution. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1555.001 Keychain |
MalwareBeaverTail |
BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
T1555.001 Keychain |
GroupContagious Interview |
Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
T1555.003 Credentials from Web Browsers |
MalwareBeaverTail |
BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. |
T1560.001 Archive via Utility |
MalwareBeaverTail |
BeaverTail has collected and archived sensitive data in a zip file. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1585 Establish Accounts |
GroupContagious Interview |
Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1614 System Location Discovery |
MalwareXORIndex Loader |
XORIndex Loader can identify the geographical location of a victim host. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |