ATT&CKSoftwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA

S1121

Malware.View on attack.mitre.org

About this malware

LITTLELAMB.WOOLTEA is a backdoor that was used by UNC5325 during Cutting Edge to deploy malware on targeted Ivanti Connect Secure VPNs and to establish persistence across system upgrades and patches.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1082
System Information Discovery

LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number.

T1083
File and Directory Discovery

LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`.

T1090
Proxy

LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy.

T1095
Non-Application Layer Protocol

LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket.

T1543
Create or Modify System Process

LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background.

T1554
Compromise Host Software Binary

LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset.

T1573.002
Asymmetric Cryptography

LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Cutting Edge Part 3 February 2024 Open source
    Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.