WARPWIRE

S1116

Malware.View on attack.mitre.org

About this malware

WARPWIRE is a Javascript credential stealer that targets plaintext passwords and usernames for exfiltration that was used during Cutting Edge to target Ivanti Connect Secure VPNs.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests.

T1056.003
Web Portal Capture

WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP.

T1059.007
JavaScript

WARPWIRE is a credential harvester written in JavaScript.

T1132.001
Standard Encoding

WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2.

T1554
Compromise Host Software Binary

WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs.

Groups that use it0

None recorded.

Campaigns1

References2

  1. Mandiant Cutting Edge January 2024 Open source
    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.
  2. Mandiant Cutting Edge Part 2 January 2024 Open source
    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.