Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has the ability to upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1027.002 Software Packing |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a variant that is packed with UPX. |
| T1027.013 Encrypted/Encoded File |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR. |
| T1036.004 Masquerade Task or Service |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login. |
| T1036.008 Masquerade File Type |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1059.001 PowerShell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses PowerShell scripts. |
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1059.005 Visual Basic |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses Word macros for execution. |
| T1070.004 File Deletion |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution. |
| T1070.006 Timestomp |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can use the |
| T1071.001 Web Protocols |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information. |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1095 Non-Application Layer Protocol |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic. |
| T1105 Ingress Tool Transfer |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
| T1129 Shared Modules |
MalwareOSX_OCEANLOTUS.D | For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`. |
| T1132.001 Standard Encoding |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a decode routine combining bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded. If the computation for the variable XOR key turns out to be 0, the default XOR key of 0x1B is used. This routine is also referenced as the `rotate` function in reporting. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via |
| T1497.001 System Checks |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
| T1553.001 Gatekeeper Bypass |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses the command |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
| T1560.003 Archive via Custom Method |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk. |
| T1564.001 Hidden Files and Directories |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden. |
| T1571 Non-Standard Port |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2. |
| T1573.001 Symmetric Cryptography |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.