ATT&CKSoftwareSpicyOmelette

SpicyOmelette

S0646

Malware.View on attack.mitre.org

About this malware

SpicyOmelette is a JavaScript based remote access tool that has been used by Cobalt Group since at least 2018.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1005
Data from Local System

SpicyOmelette has collected data and other information from a compromised host.

T1016
System Network Configuration Discovery

SpicyOmelette can identify the IP of a compromised system.

T1018
Remote System Discovery

SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments.

T1059.007
JavaScript

SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host.

T1082
System Information Discovery

SpicyOmelette can identify the system name of a compromised host.

T1105
Ingress Tool Transfer

SpicyOmelette can download malicious files from threat actor controlled AWS URL's.

T1204.001
Malicious Link

SpicyOmelette has been executed through malicious links within spearphishing emails.

T1518
Software Discovery

SpicyOmelette can enumerate running software on a targeted system.

T1518.001
Security Software Discovery

SpicyOmelette can check for the presence of 29 different antivirus tools.

T1553.002
Code Signing

SpicyOmelette has been signed with valid digital certificates.

T1566.002
Spearphishing Link

SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Secureworks GOLD KINGSWOOD September 2018 Open source
    CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.