ATT&CKSoftwareGLASSTOKEN

GLASSTOKEN

S1117

Malware.View on attack.mitre.org

About this malware

GLASSTOKEN is a custom web shell used by threat actors during Cutting Edge to execute commands on compromised Ivanti Secure Connect VPNs.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.001
PowerShell

GLASSTOKEN can use PowerShell for command execution.

T1132.001
Standard Encoding

GLASSTOKEN has hexadecimal and Base64 encoded C2 content.

T1140
Deobfuscate/Decode Files or Information

GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests.

T1505.003
Web Shell

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Volexity Ivanti Zero-Day Exploitation January 2024 Open source
    Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.