Malware.View on attack.mitre.org
LITTLELAMB.WOOLTEA is a backdoor that was used by UNC5325 during Cutting Edge to deploy malware on targeted Ivanti Connect Secure VPNs and to establish persistence across system upgrades and patches.
| Technique | Procedure example |
|---|---|
| T1082 System Information Discovery |
LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number. |
| T1083 File and Directory Discovery |
LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`. |
| T1090 Proxy |
LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy. |
| T1095 Non-Application Layer Protocol |
LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket. |
| T1543 Create or Modify System Process |
LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background. |
| T1554 Compromise Host Software Binary |
LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset. |
| T1573.002 Asymmetric Cryptography |
LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.