Chrommme

S0667

Malware.View on attack.mitre.org

About this malware

Chrommme is a backdoor tool written using the Microsoft Foundation Class (MFC) framework that was first reported in June 2021; security researchers noted infrastructure overlaps with Gelsemium malware.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

Chrommme can collect data from a local system.

T1016
System Network Configuration Discovery

Chrommme can enumerate the IP address of a compromised host.

T1027.013
Encrypted/Encoded File

Chrommme can encrypt sections of its code to evade detection.

T1029
Scheduled Transfer

Chrommme can set itself to sleep before requesting a new command from C2.

T1033
System Owner/User Discovery

Chrommme can retrieve the username from a targeted system.

T1041
Exfiltration Over C2 Channel

Chrommme can exfiltrate collected data via C2.

T1074.001
Local Data Staging

Chrommme can store captured system information locally prior to exfiltration.

T1082
System Information Discovery

Chrommme has the ability to obtain the computer name of a compromised host.

T1105
Ingress Tool Transfer

Chrommme can download its code from C2.

T1106
Native API

Chrommme can use Windows API including `WinExec` for execution.

T1113
Screen Capture

Chrommme has the ability to capture screenshots.

T1140
Deobfuscate/Decode Files or Information

Chrommme can decrypt its encrypted internal code.

T1560
Archive Collected Data

Chrommme can encrypt and store on disk collected data before exfiltration.

T1680
Local Storage Discovery

Chrommme has the ability to list drives.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET Gelsemium June 2021 Open source
    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.