ATT&CKSoftwareFRAMESTING

FRAMESTING

S1120

Malware.View on attack.mitre.org

About this malware

FRAMESTING is a Python web shell that was used during Cutting Edge to embed into an Ivanti Connect Secure Python package for command execution.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1001
Data Obfuscation

FRAMESTING can send and receive zlib compressed data within `POST` requests.

T1001.003
Protocol or Service Impersonation

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

T1059.006
Python

FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.

T1071.001
Web Protocols

FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data.

T1140
Deobfuscate/Decode Files or Information

FRAMESTING can decompress data received within `POST` requests.

T1505.003
Web Shell

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary

FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.`

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Cutting Edge Part 2 January 2024 Open source
    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.