ATT&CKReferencesRed Canary SocGholish March 2024

Red Canary SocGholish March 2024

Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSocGholish

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1027.015
Compression
MalwareSocGholish

The SocGholish JavaScript payload has been delivered within a compressed ZIP archive.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
GroupMustard Tempest

Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareSocGholish

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

T1059.007
JavaScript
MalwareSocGholish

The SocGholish payload is executed as JavaScript.

T1074.001
Local Data Staging
MalwareSocGholish

SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`.

T1082
System Information Discovery
MalwareSocGholish

SocGholish has the ability to enumerate system information including the victim computer name.

T1105
Ingress Tool Transfer
MalwareSocGholish

SocGholish can download additional malware to infected hosts.

T1189
Drive-by Compromise
GroupMustard Tempest

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1482
Domain Trust Discovery
MalwareSocGholish

SocGholish can profile compromised systems to identify domain trust relationships.

T1584.001
Domains
GroupMustard Tempest

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

T1608.004
Drive-by Target
GroupMustard Tempest

Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.