ATT&CKReferencesSocket GlassWorm January 2026

Socket GlassWorm January 2026

Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGlassWorm

GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads.

T1027.013
Encrypted/Encoded File
MalwareGlassWorm

GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1074.001
Local Data Staging
MalwareGlassWorm

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1082
System Information Discovery
MalwareGlassWorm

GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts.

T1102.001
Dead Drop Resolver
MalwareGlassWorm

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1105
Ingress Tool Transfer
MalwareGlassWorm

GlassWorm has downloaded additional payloads from C2.

T1124
System Time Discovery
MalwareGlassWorm

GlassWorm has the ability to check the system’s time zone on the victim device.

T1140
Deobfuscate/Decode Files or Information
MalwareGlassWorm

GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

T1213.003
Code Repositories
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

T1213.006
Databases
MalwareGlassWorm

GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`.

T1217
Browser Information Discovery
MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

T1480
Execution Guardrails
MalwareGlassWorm

GlassWorm has utilized logic to avoid executing on Russian based devices.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1555.001
Keychain
MalwareGlassWorm

GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`.

T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1560.001
Archive via Utility
MalwareGlassWorm

GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`.

T1602.002
Network Device Configuration Dump
MalwareGlassWorm

GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`.

T1614
System Location Discovery
MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

T1614.001
System Language Discovery
MalwareGlassWorm

GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device.

T1657
Financial Theft
MalwareGlassWorm

GlassWorm has the ability to steal credentials for cryptocurrency wallets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.