Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareGelsemium | Gelsemium can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareChrommme | Chrommme can collect data from a local system. |
| T1008 Fallback Channels |
MalwareGelsemium | Gelsemium can use multiple domains and protocols in C2. |
| T1012 Query Registry |
MalwareGelsemium | Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis. |
| T1016 System Network Configuration Discovery |
MalwareChrommme | Chrommme can enumerate the IP address of a compromised host. |
| T1027.011 Fileless Storage |
MalwareGelsemium | Gelsemium can store its components in the Registry. |
| T1027.013 Encrypted/Encoded File |
MalwareChrommme | Chrommme can encrypt sections of its code to evade detection. |
| T1027.015 Compression |
MalwareGelsemium | Gelsemium has the ability to compress its components. |
| T1027.016 Junk Code Insertion |
MalwareGelsemium | Gelsemium can use junk code to hide functions and evade detection. |
| T1029 Scheduled Transfer |
MalwareChrommme | Chrommme can set itself to sleep before requesting a new command from C2. |
| T1033 System Owner/User Discovery |
MalwareGelsemium | Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareChrommme | Chrommme can retrieve the username from a targeted system. |
| T1036.001 Invalid Code Signature |
MalwareGelsemium | Gelsemium has used unverified signatures on malicious DLLs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGelsemium | Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value |
| T1041 Exfiltration Over C2 Channel |
MalwareChrommme | Chrommme can exfiltrate collected data via C2. |
| T1055.001 Dynamic-link Library Injection |
MalwareGelsemium | Gelsemium has the ability to inject DLLs into specific processes. |
| T1057 Process Discovery |
MalwareGelsemium | Gelsemium can enumerate running processes. |
| T1059.003 Windows Command Shell |
MalwareGelsemium | Gelsemium can use a batch script to delete itself. |
| T1070.004 File Deletion |
MalwareGelsemium | Gelsemium can delete its dropper component from the targeted system. |
| T1070.006 Timestomp |
MalwareGelsemium | Gelsemium has the ability to perform timestomping of files on targeted systems. |
| T1071.001 Web Protocols |
MalwareGelsemium | Gelsemium can use HTTP/S in C2 communications. |
| T1071.004 DNS |
MalwareGelsemium | Gelsemium has the ability to use DNS in communication with C2. |
| T1074.001 Local Data Staging |
MalwareChrommme | Chrommme can store captured system information locally prior to exfiltration. |
| T1082 System Information Discovery |
MalwareChrommme | Chrommme has the ability to obtain the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwareGelsemium | Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture. |
| T1083 File and Directory Discovery |
MalwareGelsemium | Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion. |
| T1095 Non-Application Layer Protocol |
MalwareGelsemium | Gelsemium has the ability to use TCP and UDP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareGelsemium | Gelsemium can download additional plug-ins to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareChrommme | Chrommme can download its code from C2. |
| T1106 Native API |
MalwareChrommme | Chrommme can use Windows API including `WinExec` for execution. |
| T1106 Native API |
MalwareGelsemium | Gelsemium has the ability to use various Windows API functions to perform tasks. |
| T1112 Modify Registry |
MalwareGelsemium | Gelsemium can modify the Registry to store its components. |
| T1113 Screen Capture |
MalwareChrommme | Chrommme has the ability to capture screenshots. |
| T1134 Access Token Manipulation |
MalwareGelsemium | Gelsemium can use token manipulation to bypass UAC on Windows7 systems. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGelsemium | Gelsemium can decompress and decrypt DLLs and shellcode. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChrommme | Chrommme can decrypt its encrypted internal code. |
| T1497 Virtualization/Sandbox Evasion |
MalwareGelsemium | Gelsemium can use junk code to generate random activity to obscure malware behavior. |
| T1518.001 Security Software Discovery |
MalwareGelsemium | Gelsemium can check for the presence of specific security products. |
| T1543.003 Windows Service |
MalwareGelsemium | Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGelsemium | Gelsemium can set persistence with a Registry run key. |
| T1547.012 Print Processors |
MalwareGelsemium | Gelsemium can drop itself in |
| T1548.002 Bypass User Account Control |
MalwareGelsemium | Gelsemium can bypass UAC to elevate process privileges on a compromised host. |
| T1559.001 Component Object Model |
MalwareGelsemium | Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process. |
| T1560 Archive Collected Data |
MalwareChrommme | Chrommme can encrypt and store on disk collected data before exfiltration. |
| T1568 Dynamic Resolution |
MalwareGelsemium | Gelsemium can use dynamic DNS domain names in C2. |
| T1620 Reflective Code Loading |
MalwareGelsemium | Gelsemium can use custom shellcode to map embedded DLLs into memory. |
| T1680 Local Storage Discovery |
MalwareChrommme | Chrommme has the ability to list drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.