Malware.View on attack.mitre.org
SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1027.013 Encrypted/Encoded File |
SocGholish has single or double Base-64 encoded references to its second-stage server URLs. |
| T1027.015 Compression |
The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1033 System Owner/User Discovery |
SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
SocGholish has been named `AutoUpdater.js` to mimic legitimate update files. |
| T1047 Windows Management Instrumentation |
SocGholish has used WMI calls for script execution and system profiling. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
| T1057 Process Discovery |
SocGholish can list processes on targeted hosts. |
| T1059.007 JavaScript |
The SocGholish payload is executed as JavaScript. |
| T1074.001 Local Data Staging |
SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1082 System Information Discovery |
SocGholish has the ability to enumerate system information including the victim computer name. |
| T1102 Web Service |
SocGholish has used Amazon Web Services to host second-stage servers. |
| T1105 Ingress Tool Transfer |
SocGholish can download additional malware to infected hosts. |
| T1189 Drive-by Compromise |
SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1204.001 Malicious Link |
SocGholish has lured victims into interacting with malicious links on compromised websites for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.