ATT&CKReferencesESET Gelsemium June 2021

ESET Gelsemium June 2021

Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples47

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGelsemium

Gelsemium can collect data from a compromised host.

T1005
Data from Local System
MalwareChrommme

Chrommme can collect data from a local system.

T1008
Fallback Channels
MalwareGelsemium

Gelsemium can use multiple domains and protocols in C2.

T1012
Query Registry
MalwareGelsemium

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1016
System Network Configuration Discovery
MalwareChrommme

Chrommme can enumerate the IP address of a compromised host.

T1027.011
Fileless Storage
MalwareGelsemium

Gelsemium can store its components in the Registry.

T1027.013
Encrypted/Encoded File
MalwareChrommme

Chrommme can encrypt sections of its code to evade detection.

T1027.015
Compression
MalwareGelsemium

Gelsemium has the ability to compress its components.

T1027.016
Junk Code Insertion
MalwareGelsemium

Gelsemium can use junk code to hide functions and evade detection.

T1029
Scheduled Transfer
MalwareChrommme

Chrommme can set itself to sleep before requesting a new command from C2.

T1033
System Owner/User Discovery
MalwareGelsemium

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1033
System Owner/User Discovery
MalwareChrommme

Chrommme can retrieve the username from a targeted system.

T1036.001
Invalid Code Signature
MalwareGelsemium

Gelsemium has used unverified signatures on malicious DLLs.

T1036.005
Match Legitimate Resource Name or Location
MalwareGelsemium

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1041
Exfiltration Over C2 Channel
MalwareChrommme

Chrommme can exfiltrate collected data via C2.

T1055.001
Dynamic-link Library Injection
MalwareGelsemium

Gelsemium has the ability to inject DLLs into specific processes.

T1057
Process Discovery
MalwareGelsemium

Gelsemium can enumerate running processes.

T1059.003
Windows Command Shell
MalwareGelsemium

Gelsemium can use a batch script to delete itself.

T1070.004
File Deletion
MalwareGelsemium

Gelsemium can delete its dropper component from the targeted system.

T1070.006
Timestomp
MalwareGelsemium

Gelsemium has the ability to perform timestomping of files on targeted systems.

T1071.001
Web Protocols
MalwareGelsemium

Gelsemium can use HTTP/S in C2 communications.

T1071.004
DNS
MalwareGelsemium

Gelsemium has the ability to use DNS in communication with C2.

T1074.001
Local Data Staging
MalwareChrommme

Chrommme can store captured system information locally prior to exfiltration.

T1082
System Information Discovery
MalwareChrommme

Chrommme has the ability to obtain the computer name of a compromised host.

T1082
System Information Discovery
MalwareGelsemium

Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture.

T1083
File and Directory Discovery
MalwareGelsemium

Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion.

T1095
Non-Application Layer Protocol
MalwareGelsemium

Gelsemium has the ability to use TCP and UDP in C2 communications.

T1105
Ingress Tool Transfer
MalwareGelsemium

Gelsemium can download additional plug-ins to a compromised host.

T1105
Ingress Tool Transfer
MalwareChrommme

Chrommme can download its code from C2.

T1106
Native API
MalwareChrommme

Chrommme can use Windows API including `WinExec` for execution.

T1106
Native API
MalwareGelsemium

Gelsemium has the ability to use various Windows API functions to perform tasks.

T1112
Modify Registry
MalwareGelsemium

Gelsemium can modify the Registry to store its components.

T1113
Screen Capture
MalwareChrommme

Chrommme has the ability to capture screenshots.

T1134
Access Token Manipulation
MalwareGelsemium

Gelsemium can use token manipulation to bypass UAC on Windows7 systems.

T1140
Deobfuscate/Decode Files or Information
MalwareGelsemium

Gelsemium can decompress and decrypt DLLs and shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareChrommme

Chrommme can decrypt its encrypted internal code.

T1497
Virtualization/Sandbox Evasion
MalwareGelsemium

Gelsemium can use junk code to generate random activity to obscure malware behavior.

T1518.001
Security Software Discovery
MalwareGelsemium

Gelsemium can check for the presence of specific security products.

T1543.003
Windows Service
MalwareGelsemium

Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts.

T1547.001
Registry Run Keys / Startup Folder
MalwareGelsemium

Gelsemium can set persistence with a Registry run key.

T1547.012
Print Processors
MalwareGelsemium

Gelsemium can drop itself in C:\Windows\System32\spool\prtprocs\x64\winprint.dll to be loaded automatically by the spoolsv Windows service.

T1548.002
Bypass User Account Control
MalwareGelsemium

Gelsemium can bypass UAC to elevate process privileges on a compromised host.

T1559.001
Component Object Model
MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

T1560
Archive Collected Data
MalwareChrommme

Chrommme can encrypt and store on disk collected data before exfiltration.

T1568
Dynamic Resolution
MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

T1620
Reflective Code Loading
MalwareGelsemium

Gelsemium can use custom shellcode to map embedded DLLs into memory.

T1680
Local Storage Discovery
MalwareChrommme

Chrommme has the ability to list drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.