SPICYOMELETTE

SPICYOMELETTESpicyOmelette

Description

In 2018, CTU researchers observed several GOLD KINGSWOOD campaigns involving SpicyOmelette, a tool used by the group during initial exploitation of an organization. This sophisticated JavaScript remote access tool is generally delivered via phishing, and it uses multiple defense evasion techniques to hinder prevention and detection activities. GOLD KINGSWOOD delivered SpicyOmelette through a phishing email containing a shortened link that appeared to be a PDF document attachment. When clicked, the link used the Google AppEngine to redirect the system to a GOLD KINGSWOOD-controlled Amazon Web Services (AWS) URL that installed a signed JavaScript file, which was SpicyOmelette.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
GoldMax
Software
GoldFinder
Actor
SneakyChef
Actor
GOLD DUPONT
Actor
GoldenJackal
Software
JS Flash
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.