Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareGlassWorm | GlassWorm has utilized Google Calendar as backup C2. |
| T1027.013 Encrypted/Encoded File |
MalwareGlassWorm | GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field. |
| T1036 Masquerading |
MalwareGlassWorm | GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects. |
| T1082 System Information Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1105 Ingress Tool Transfer |
MalwareGlassWorm | GlassWorm has downloaded additional payloads from C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.