ATT&CKReferencesSymantec Troll Stealer 2024

Symantec Troll Stealer 2024

Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTroll Stealer

Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note.

T1016
System Network Configuration Discovery
MalwareGomir

Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses.

T1018
Remote System Discovery
MalwareGomir

Gomir probes arbitrary network endpoints for TCP connectivity.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoBear

GoBear is installed through droppers masquerading as legitimate, signed software installers.

T1036.005
Match Legitimate Resource Name or Location
MalwareTroll Stealer

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1053.003
Cron
MalwareGomir

Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges.

T1059.004
Unix Shell
MalwareGomir

Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands.

T1069.001
Local Groups
MalwareGomir

Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments.

T1070.004
File Deletion
MalwareGomir

Gomir deletes its original executable and terminates its original process after creating a systemd service.

T1071.001
Web Protocols
MalwareGomir

Gomir periodically communicates to its command and control infrastructure through HTTP POST requests.

T1082
System Information Discovery
MalwareTroll Stealer

Troll Stealer can collect local system information.

T1082
System Information Discovery
MalwareGomir

Gomir collects information on infected systems such as hostname, username, CPU, and RAM information.

T1083
File and Directory Discovery
MalwareGomir

Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems.

T1090.001
Internal Proxy
MalwareGomir

Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks.

T1113
Screen Capture
MalwareTroll Stealer

Troll Stealer can capture screenshots from victim machines.

T1132.001
Standard Encoding
MalwareGomir

Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure.

T1213
Data from Information Repositories
MalwareTroll Stealer

Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems.

T1217
Browser Information Discovery
MalwareTroll Stealer

Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions.

T1543.002
Systemd Service
MalwareGomir

Gomir creates a systemd service named `syslogd` for persistence.

T1552.004
Private Keys
MalwareTroll Stealer

Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems.

T1553.002
Code Signing
MalwareGoBear

GoBear uses stolen legitimate code signing certificates for defense evasion.

T1573
Encrypted Channel
MalwareGomir

Gomir uses a custom encryption algorithm for content sent to command and control infrastructure.

T1573.002
Asymmetric Cryptography
MalwareGomir

Gomir uses reverse proxy functionality that employs SSL to encrypt communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.