ATT&CKReferencesSocGholish-update

SocGholish-update

Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSocGholish

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
GroupMustard Tempest

Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`.

T1036.005
Match Legitimate Resource Name or Location
MalwareSocGholish

SocGholish has been named `AutoUpdater.js` to mimic legitimate update files.

T1047
Windows Management Instrumentation
MalwareSocGholish

SocGholish has used WMI calls for script execution and system profiling.

T1059.007
JavaScript
MalwareSocGholish

The SocGholish payload is executed as JavaScript.

T1082
System Information Discovery
MalwareSocGholish

SocGholish has the ability to enumerate system information including the victim computer name.

T1189
Drive-by Compromise
GroupMustard Tempest

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1189
Drive-by Compromise
MalwareSocGholish

SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates.

T1204.001
Malicious Link
MalwareSocGholish

SocGholish has lured victims into interacting with malicious links on compromised websites for execution.

T1204.001
Malicious Link
GroupMustard Tempest

Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails.

T1482
Domain Trust Discovery
MalwareSocGholish

SocGholish can profile compromised systems to identify domain trust relationships.

T1566.002
Spearphishing Link
GroupMustard Tempest

Mustard Tempest has sent victims emails containing links to compromised websites.

T1566.002
Spearphishing Link
MalwareSocGholish

SocGholish has been spread via emails containing malicious links.

T1584.001
Domains
GroupMustard Tempest

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

T1608.004
Drive-by Target
GroupMustard Tempest

Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download.

T1608.006
SEO Poisoning
GroupMustard Tempest

Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.