ATT&CKReferencesAikido GlassWorm October 2025

Aikido GlassWorm October 2025

Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.018
Invisible Unicode
MalwareGlassWorm

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1036
Masquerading
MalwareGlassWorm

GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1102.001
Dead Drop Resolver
MalwareGlassWorm

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.