T1016 System Network Configuration Discovery |
MalwareHexEval Loader |
HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host. |
T1027.013 Encrypted/Encoded File |
MalwareHexEval Loader |
HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
T1033 System Owner/User Discovery |
MalwareHexEval Loader |
HexEval Loader has collected the username from the victim host. |
T1036.005 Match Legitimate Resource Name or Location |
MalwareHexEval Loader |
HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects. |
T1041 Exfiltration Over C2 Channel |
MalwareHexEval Loader |
HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1056.001 Keylogging |
MalwareHexEval Loader |
HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems. |
T1059.007 JavaScript |
MalwareHexEval Loader |
HexEval Loader has executed malicious JavaScript code. |
T1071.001 Web Protocols |
MalwareHexEval Loader |
HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
T1082 System Information Discovery |
MalwareHexEval Loader |
HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting. |
T1083 File and Directory Discovery |
MalwareBeaverTail |
BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1105 Ingress Tool Transfer |
MalwareHexEval Loader |
HexEval Loader has been used to download a malicious payload to include BeaverTail. |
T1140 Deobfuscate/Decode Files or Information |
MalwareHexEval Loader |
HexEval Loader has decoded its payload prior to execution. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1480 Execution Guardrails |
GroupContagious Interview |
Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads. |
T1497 Virtualization/Sandbox Evasion |
GroupContagious Interview |
Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection. |
T1555.001 Keychain |
GroupContagious Interview |
Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
T1555.001 Keychain |
MalwareBeaverTail |
BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
T1555.003 Credentials from Web Browsers |
MalwareBeaverTail |
BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. |
T1583.001 Domains |
GroupContagious Interview |
Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. |
T1583.006 Web Services |
GroupContagious Interview |
Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. |
T1585 Establish Accounts |
GroupContagious Interview |
Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. |
T1585.002 Email Accounts |
GroupContagious Interview |
Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1614 System Location Discovery |
MalwareHexEval Loader |
HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |
T1684.001 Impersonation |
GroupContagious Interview |
Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. |
T1685 Disable or Modify Tools |
GroupContagious Interview |
Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection. |