ATT&CKReferencesGlitch-Cat Green Lambert ATTCK Oct 2021

Glitch-Cat Green Lambert ATTCK Oct 2021

Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareGreen Lambert

Green Lambert can obtain proxy information from a victim's machine using system environment variables.

T1027
Obfuscated Files or Information
MalwareGreen Lambert

Green Lambert has encrypted strings.

T1036.004
Masquerade Task or Service
MalwareGreen Lambert

Green Lambert has created a new executable named `Software Update Check` to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareGreen Lambert

Green Lambert has been disguised as a Growl help file.

T1037.004
RC Scripts
MalwareGreen Lambert

Green Lambert can add init.d and rc.d files in the /etc folder to establish persistence.

T1059.004
Unix Shell
MalwareGreen Lambert

Green Lambert can use shell scripts for execution, such as /bin/sh -c.

T1070.004
File Deletion
MalwareGreen Lambert

Green Lambert can delete the original executable after initial installation in addition to unused functions.

T1071.004
DNS
MalwareGreen Lambert

Green Lambert can use DNS for C2 communications.

T1082
System Information Discovery
MalwareGreen Lambert

Green Lambert can use `uname` to identify the operating system name, version, and processor type.

T1090
Proxy
MalwareGreen Lambert

Green Lambert can use proxies for C2 traffic.

T1124
System Time Discovery
MalwareGreen Lambert

Green Lambert can collect the date and time from a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareGreen Lambert

Green Lambert can use multiple custom routines to decrypt strings prior to execution.

T1543.001
Launch Agent
MalwareGreen Lambert

Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to true, ensuring the `com.apple.GrowlHelper.plist` file runs every time a user logs in.

T1543.004
Launch Daemon
MalwareGreen Lambert

Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence.

T1546.004
Unix Shell Configuration Modification
MalwareGreen Lambert

Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells.

T1547.015
Login Items
MalwareGreen Lambert

Green Lambert can add Login Items to establish persistence.

T1555.001
Keychain
MalwareGreen Lambert

Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.