Real-world descriptions of how a group, tool or campaign used a technique.
33 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareXCSSET | XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders. |
| T1027.013 Encrypted/Encoded File |
MalwareXCSSET | Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell. |
| T1036 Masquerading |
MalwareXCSSET | XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata. |
| T1041 Exfiltration Over C2 Channel |
MalwareXCSSET | XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel. |
| T1056.002 GUI Input Capture |
MalwareXCSSET | XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1059.004 Unix Shell |
MalwareXCSSET | XCSSET uses a shell script to execute Mach-o files and |
| T1068 Exploitation for Privilege Escalation |
MalwareXCSSET | XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1082 System Information Discovery |
MalwareXCSSET | XCSSET identifies the macOS version and uses |
| T1083 File and Directory Discovery |
MalwareXCSSET | XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`. |
| T1087 Account Discovery |
MalwareXCSSET | XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| T1098.004 SSH Authorized Keys |
MalwareXCSSET | XCSSET will create an ssh key if necessary with the |
| T1105 Ingress Tool Transfer |
MalwareXCSSET | XCSSET downloads browser specific AppleScript modules using a constructed URL with the |
| T1113 Screen Capture |
MalwareXCSSET | XCSSET saves a screen capture of the victim's system with a numbered filename and |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareXCSSET | XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
| T1222.002 Linux and Mac Permissions |
MalwareXCSSET | XCSSET uses the |
| T1486 Data Encrypted for Impact |
MalwareXCSSET | XCSSET performs AES-CBC encryption on files under |
| T1497.003 Time Based Checks |
MalwareXCSSET | Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, |
| T1518 Software Discovery |
MalwareXCSSET | XCSSET uses |
| T1518.001 Security Software Discovery |
MalwareXCSSET | XCSSET searches firewall configuration files located in |
| T1539 Steal Web Session Cookie |
MalwareXCSSET | XCSSET uses |
| T1543.004 Launch Daemon |
MalwareXCSSET | XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim. |
| T1546 Event Triggered Execution |
MalwareXCSSET | XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process. |
| T1546.004 Unix Shell Configuration Modification |
MalwareXCSSET | Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file. |
| T1548.006 TCC Manipulation |
MalwareXCSSET | For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access. |
| T1553.001 Gatekeeper Bypass |
MalwareXCSSET | XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13). |
| T1554 Compromise Host Software Binary |
MalwareXCSSET | XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules. |
| T1560 Archive Collected Data |
MalwareXCSSET | XCSSET will compress entire |
| T1564.001 Hidden Files and Directories |
MalwareXCSSET | XCSSET uses a hidden folder named |
| T1569.001 Launchctl |
MalwareXCSSET | XCSSET loads a system level launchdaemon using the |
| T1573.001 Symmetric Cryptography |
MalwareXCSSET | XCSSET uses RC4 encryption over TCP to communicate with its C2 server. |
| T1574.006 Dynamic Linker Hijacking |
MalwareXCSSET | XCSSET adds malicious file paths to the |
| T1614.001 System Language Discovery |
MalwareXCSSET | XCSSET uses AppleScript to check the host's language and location with the command |
| T1647 Plist File Modification |
MalwareXCSSET | In older versions, XCSSET uses the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.