ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0352×

28 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.

T1016
System Network Configuration Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host.

T1027.002
Software Packing
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a variant that is packed with UPX.

T1027.013
Encrypted/Encoded File
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR.

T1036.004
Masquerade Task or Service
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login.

T1036.008
Masquerade File Type
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1059.001
PowerShell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses PowerShell scripts.

T1059.004
Unix Shell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1059.005
Visual Basic
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses Word macros for execution.

T1070.004
File Deletion
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution.

T1070.006
Timestomp
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1071.001
Web Protocols
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information.

T1082
System Information Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the ioreg command to gather some of this information.

T1095
Non-Application Layer Protocol
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic.

T1105
Ingress Tool Transfer
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.

T1129
Shared Modules
MalwareOSX_OCEANLOTUS.D

For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`.

T1132.001
Standard Encoding
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol.

T1140
Deobfuscate/Decode Files or Information
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a decode routine combining bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded. If the computation for the variable XOR key turns out to be 0, the default XOR key of 0x1B is used. This routine is also referenced as the `rotate` function in reporting.

T1222.002
Linux and Mac Permissions
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via chmod.

T1497.001
System Checks
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time.

T1543.001
Launch Agent
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchAgents.

T1543.004
Launch Daemon
MalwareOSX_OCEANLOTUS.D

If running with root permissions, OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchDaemons.

T1553.001
Gatekeeper Bypass
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses the command xattr -d com.apple.quarantine to remove the quarantine file attribute used by Gatekeeper.

T1560.002
Archive via Library
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server.

T1560.003
Archive via Custom Method
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk.

T1564.001
Hidden Files and Directories
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden.

T1571
Non-Standard Port
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2.

T1573.001
Symmetric Cryptography
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.