Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
PHASEJAM has encoded commands with Base64. |
| T1027.013 Encrypted/Encoded File |
PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands. |
| T1036.003 Rename Legitimate Utilities |
PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script. |
| T1041 Exfiltration Over C2 Channel |
PHASEJAM has the ability to exfiltrate data from the victim appliance. |
| T1059.008 Network Device CLI |
PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code. |
| T1105 Ingress Tool Transfer |
PHASEJAM has the ability to upload files onto the compromised appliance. |
| T1140 Deobfuscate/Decode Files or Information |
PHASEJAM has the ability to decode Base64 commands and data. |
| T1489 Service Stop |
PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances. |
| T1505.003 Web Shell |
PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance. |
| T1546.004 Unix Shell Configuration Modification |
PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands. |
| T1554 Compromise Host Software Binary |
PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided. |
| T1565 Data Manipulation |
PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version. |
| T1678 Delay Execution |
PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| T1685 Disable or Modify Tools |
PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file. |
| T1685.003 Modify or Spoof Tool UI |
PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.