ATT&CKReferencesTrustwave GoldenSpy2 June 2020

Trustwave GoldenSpy2 June 2020

Trustwave SpiderLabs. (2020, June 26). GoldenSpy: Chapter Two – The Uninstaller. Retrieved July 23, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareGoldenSpy

GoldenSpy's uninstaller has base64-encoded its variables.

T1070.004
File Deletion
MalwareGoldenSpy

GoldenSpy's uninstaller can delete registry entries, files and folders, and finally itself once these tasks have been completed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.