Malware.View on attack.mitre.org
GLASSTOKEN is a custom web shell used by threat actors during Cutting Edge to execute commands on compromised Ivanti Secure Connect VPNs.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
GLASSTOKEN can use PowerShell for command execution. |
| T1132.001 Standard Encoding |
GLASSTOKEN has hexadecimal and Base64 encoded C2 content. |
| T1140 Deobfuscate/Decode Files or Information |
GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests. |
| T1505.003 Web Shell |
GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.