Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldenSpy | GoldenSpy's setup file installs initial executables under the folder |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldenSpy | GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006. |
| T1059.003 Windows Command Shell |
MalwareGoldenSpy | GoldenSpy can execute remote commands via the command-line interface. |
| T1071.001 Web Protocols |
MalwareGoldenSpy | GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication. |
| T1082 System Information Discovery |
MalwareGoldenSpy | GoldenSpy has gathered operating system information. |
| T1083 File and Directory Discovery |
MalwareGoldenSpy | GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary. |
| T1105 Ingress Tool Transfer |
MalwareGoldenSpy | GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system. |
| T1106 Native API |
MalwareGoldenSpy | GoldenSpy can execute remote commands in the Windows command shell using the |
| T1136.001 Local Account |
MalwareGoldenSpy | GoldenSpy can create new users on an infected system. |
| T1195.002 Compromise Software Supply Chain |
MalwareGoldenSpy | GoldenSpy has been packaged with a legitimate tax preparation software. |
| T1497.003 Time Based Checks |
MalwareGoldenSpy | GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system. |
| T1543.003 Windows Service |
MalwareGoldenSpy | GoldenSpy has established persistence by running in the background as an autostart service. |
| T1571 Non-Standard Port |
MalwareGoldenSpy | GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.