ATT&CKSoftwareSocGholish

SocGholish

S1124

Malware.View on attack.mitre.org

About this malware

SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1016
System Network Configuration Discovery

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1027.013
Encrypted/Encoded File

SocGholish has single or double Base-64 encoded references to its second-stage server URLs.

T1027.015
Compression

The SocGholish JavaScript payload has been delivered within a compressed ZIP archive.

T1033
System Owner/User Discovery

SocGholish can use `whoami` to obtain the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location

SocGholish has been named `AutoUpdater.js` to mimic legitimate update files.

T1047
Windows Management Instrumentation

SocGholish has used WMI calls for script execution and system profiling.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

T1057
Process Discovery

SocGholish can list processes on targeted hosts.

T1059.007
JavaScript

The SocGholish payload is executed as JavaScript.

T1074.001
Local Data Staging

SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`.

T1082
System Information Discovery

SocGholish has the ability to enumerate system information including the victim computer name.

T1102
Web Service

SocGholish has used Amazon Web Services to host second-stage servers.

T1105
Ingress Tool Transfer

SocGholish can download additional malware to infected hosts.

T1189
Drive-by Compromise

SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates.

T1204.001
Malicious Link

SocGholish has lured victims into interacting with malicious links on compromised websites for execution.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. Red Canary SocGholish March 2024 Open source
    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.
  2. Secureworks Gold Prelude Profile Open source
    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.
  3. SentinelOne SocGholish Infrastructure November 2022 Open source
    Milenkoski, A. (2022, November 7). SocGholish Diversifies and Expands Its Malware Staging Infrastructure to Counter Defenders. Retrieved March 22, 2024.
  4. SocGholish-update Open source
    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.