Malware.View on attack.mitre.org
WARPWIRE is a Javascript credential stealer that targets plaintext passwords and usernames for exfiltration that was used during Cutting Edge to target Ivanti Connect Secure VPNs.
| Technique | Procedure example |
|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1056.003 Web Portal Capture |
WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP. |
| T1059.007 JavaScript |
WARPWIRE is a credential harvester written in JavaScript. |
| T1132.001 Standard Encoding |
WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2. |
| T1554 Compromise Host Software Binary |
WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.