Chrommme — Malware Profile
Chrommme is a backdoor tool written using the Microsoft Foundation Class (MFC) framework that was first reported in June 2021; security researchers noted infrastructure overlaps with Gelsemium malware.
MITRE ATT&CK techniques (14)
- T1005 Data from Local System
- T1016 System Network Configuration Discovery
- T1027.013 Encrypted/Encoded File
- T1029 Scheduled Transfer
- T1033 System Owner/User Discovery
- T1041 Exfiltration Over C2 Channel
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1113 Screen Capture
- T1140 Deobfuscate/Decode Files or Information
- T1560 Archive Collected Data
- T1680 Local Storage Discovery