Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1027.015 Compression |
MalwareSocGholish | The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustard Tempest | Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareSocGholish | SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
| T1059.007 JavaScript |
MalwareSocGholish | The SocGholish payload is executed as JavaScript. |
| T1074.001 Local Data Staging |
MalwareSocGholish | SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1105 Ingress Tool Transfer |
MalwareSocGholish | SocGholish can download additional malware to infected hosts. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1482 Domain Trust Discovery |
MalwareSocGholish | SocGholish can profile compromised systems to identify domain trust relationships. |
| T1584.001 Domains |
GroupMustard Tempest | Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1608.004 Drive-by Target |
GroupMustard Tempest | Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.