# GlassWorm Operator

> As of 2026-05-30, GlassWorm Operator is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning supply chain, malware. Also known as GlassWorm. ATT&CK coverage spans 39 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter).

- **Nation:** N/A
- **Tracked threats:** 3
- **Categories:** SUPPLY_CHAIN, MALWARE
- **Also known as:** GlassWorm
- **As of:** 2026-05-30

## ATT&CK techniques observed

39 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (6), Collection (5), Credential Access (5), Stealth (formerly Defense Evasion) (5), Persistence (4), Resource Development (4).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 3 of 3 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 3 of 3 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 3 of 3 tracked threats
- [T1496](https://intel.threadlinqs.com/technique/T1496) Resource Hijacking — Impact — observed in 3 of 3 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 3 of 3 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 3 of 3 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 3 of 3 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 3 tracked threats

## Tracked threats

- [GlassWorm Supply Chain Attack: Fake Browser Extension & Multi-Stage RAT via Compromised Developer Packages](https://intel.threadlinqs.com/threat/TL-2026-0287) — HIGH
- [GlassWorm v3 Supply Chain Attack — 72 Malicious Open VSX Extensions, 151 GitHub Repos & ZOMBI Botnet Module](https://intel.threadlinqs.com/threat/TL-2026-0231) — HIGH
- [GlassWorm Supply Chain Campaign: 73 Malicious Open VSX Extensions Using Transitive Dependencies](https://intel.threadlinqs.com/threat/TL-2026-0224) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/GlassWorm%20Operator
