Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.018 Invisible Unicode |
MalwareGlassWorm | GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors. |
| T1036 Masquerading |
MalwareGlassWorm | GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects. |
| T1059.007 JavaScript |
MalwareGlassWorm | GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareGlassWorm | GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.