ATT&CKReferencesKoi Glassworm New Tricks December 2025

Koi Glassworm New Tricks December 2025

Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareGlassWorm

GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field.

T1027.018
Invisible Unicode
MalwareGlassWorm

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1059.002
AppleScript
MalwareGlassWorm

GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1074.001
Local Data Staging
MalwareGlassWorm

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1102.001
Dead Drop Resolver
MalwareGlassWorm

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1105
Ingress Tool Transfer
MalwareGlassWorm

GlassWorm has downloaded additional payloads from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareGlassWorm

GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads.

T1213.003
Code Repositories
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

T1518
Software Discovery
MalwareGlassWorm

GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1554
Compromise Host Software Binary
MalwareGlassWorm

GlassWorm can modify hardware wallet applications.

T1555.001
Keychain
MalwareGlassWorm

GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`.

T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1565.002
Transmitted Data Manipulation
MalwareGlassWorm

GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing.

T1602.002
Network Device Configuration Dump
MalwareGlassWorm

GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`.

T1657
Financial Theft
MalwareGlassWorm

GlassWorm has the ability to steal credentials for cryptocurrency wallets.

T1678
Delay Execution
MalwareGlassWorm

GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.