ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0658×

33 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareXCSSET

XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders.

T1027.013
Encrypted/Encoded File
MalwareXCSSET

Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell.

T1036
Masquerading
MalwareXCSSET

XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata.

T1041
Exfiltration Over C2 Channel
MalwareXCSSET

XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel.

T1056.002
GUI Input Capture
MalwareXCSSET

XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.

T1059.004
Unix Shell
MalwareXCSSET

XCSSET uses a shell script to execute Mach-o files and osacompile commands such as, osacompile -x -o xcode.app main.applescript.

T1068
Exploitation for Privilege Escalation
MalwareXCSSET

XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP.

T1082
System Information Discovery
MalwareXCSSET

XCSSET identifies the macOS version and uses ioreg to determine serial number.

T1083
File and Directory Discovery
MalwareXCSSET

XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`.

T1087
Account Discovery
MalwareXCSSET

XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data.

T1098.004
SSH Authorized Keys
MalwareXCSSET

XCSSET will create an ssh key if necessary with the ssh-keygen -t rsa -f $HOME/.ssh/id_rsa -P command. XCSSET will upload a private key file to the server to remotely access the host without a password.

T1105
Ingress Tool Transfer
MalwareXCSSET

XCSSET downloads browser specific AppleScript modules using a constructed URL with the curl command, https://" & domain & "/agent/scripts/" & moduleName & ".applescript.

T1113
Screen Capture
MalwareXCSSET

XCSSET saves a screen capture of the victim's system with a numbered filename and .jpg extension. Screen captures are taken at specified intervals based on the system.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareXCSSET

XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods target_integrator.rb files under the /Library/Ruby/Gems folder or enumerates all .xcodeproj folders under a given directory. XCSSET then downloads a script and Mach-O file into the Xcode project folder.

T1222.002
Linux and Mac Permissions
MalwareXCSSET

XCSSET uses the chmod +x command to grant executable permissions to the malicious file.

T1486
Data Encrypted for Impact
MalwareXCSSET

XCSSET performs AES-CBC encryption on files under ~/Documents, ~/Downloads, and
~/Desktop with a fixed key and renames files to give them a .enc extension. Only files with sizes
less than 500MB are encrypted.

T1497.003
Time Based Checks
MalwareXCSSET

Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, .report. After the elapsed time, XCSSET executes additional modules.

T1518
Software Discovery
MalwareXCSSET

XCSSET uses ps aux with the grep command to enumerate common browsers and system processes potentially impacting XCSSET's exfiltration capabilities.

T1518.001
Security Software Discovery
MalwareXCSSET

XCSSET searches firewall configuration files located in /Library/Preferences/ and uses csrutil status to determine if System Integrity Protection is enabled.

T1539
Steal Web Session Cookie
MalwareXCSSET

XCSSET uses scp to access the ~/Library/Cookies/Cookies.binarycookies file.

T1543.004
Launch Daemon
MalwareXCSSET

XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim.

T1546
Event Triggered Execution
MalwareXCSSET

XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process.

T1546.004
Unix Shell Configuration Modification
MalwareXCSSET

Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file.

T1548.006
TCC Manipulation
MalwareXCSSET

For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access.

T1553.001
Gatekeeper Bypass
MalwareXCSSET

XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13).

T1554
Compromise Host Software Binary
MalwareXCSSET

XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules.

T1560
Archive Collected Data
MalwareXCSSET

XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.

T1564.001
Hidden Files and Directories
MalwareXCSSET

XCSSET uses a hidden folder named .xcassets and .git to embed itself in Xcode.

T1569.001
Launchctl
MalwareXCSSET

XCSSET loads a system level launchdaemon using the launchctl load -w command from /System/Librarby/LaunchDaemons/ssh.plist.

T1573.001
Symmetric Cryptography
MalwareXCSSET

XCSSET uses RC4 encryption over TCP to communicate with its C2 server.

T1574.006
Dynamic Linker Hijacking
MalwareXCSSET

XCSSET adds malicious file paths to the DYLD_FRAMEWORK_PATH and DYLD_LIBRARY_PATH environment variables to execute malicious code.

T1614.001
System Language Discovery
MalwareXCSSET

XCSSET uses AppleScript to check the host's language and location with the command user locale of (get system info).

T1647
Plist File Modification
MalwareXCSSET

In older versions, XCSSET uses the plutil command to modify the LSUIElement, DFBundleDisplayName, and CFBundleIdentifier keys in the /Contents/Info.plist file to change how XCSSET is visible on the system. In later versions, XCSSET leverages a third-party notarized `dockutil` tool to modify the `.plist` file responsible for presenting applications to the user in the Dock and LaunchPad to point to a malicious application.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.