Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustard Tempest | Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSocGholish | SocGholish has been named `AutoUpdater.js` to mimic legitimate update files. |
| T1047 Windows Management Instrumentation |
MalwareSocGholish | SocGholish has used WMI calls for script execution and system profiling. |
| T1059.007 JavaScript |
MalwareSocGholish | The SocGholish payload is executed as JavaScript. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1189 Drive-by Compromise |
MalwareSocGholish | SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1204.001 Malicious Link |
MalwareSocGholish | SocGholish has lured victims into interacting with malicious links on compromised websites for execution. |
| T1204.001 Malicious Link |
GroupMustard Tempest | Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails. |
| T1482 Domain Trust Discovery |
MalwareSocGholish | SocGholish can profile compromised systems to identify domain trust relationships. |
| T1566.002 Spearphishing Link |
GroupMustard Tempest | Mustard Tempest has sent victims emails containing links to compromised websites. |
| T1566.002 Spearphishing Link |
MalwareSocGholish | SocGholish has been spread via emails containing malicious links. |
| T1584.001 Domains |
GroupMustard Tempest | Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1608.004 Drive-by Target |
GroupMustard Tempest | Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
| T1608.006 SEO Poisoning |
GroupMustard Tempest | Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.