Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMacMa | MacMa can collect then exfiltrate files from the compromised system. |
| T1016 System Network Configuration Discovery |
MalwareMacMa | MacMa can collect IP addresses from a compromised host. |
| T1021 Remote Services |
MalwareMacMa | MacMa can manage remote screen sessions. |
| T1033 System Owner/User Discovery |
MalwareMacMa | MacMa can collect the username from the compromised machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareMacMa | MacMa exfiltrates data from a supplied path over its C2 channel. |
| T1056.001 Keylogging |
MalwareMacMa | MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords. |
| T1057 Process Discovery |
MalwareMacMa | MacMa can enumerate running processes. |
| T1059.004 Unix Shell |
MalwareMacMa | MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1070.004 File Deletion |
MalwareMacMa | MacMa can delete itself from the compromised computer. |
| T1070.006 Timestomp |
MalwareMacMa | MacMa has the capability to create and modify file timestamps. |
| T1074.001 Local Data Staging |
MalwareMacMa | MacMa has stored collected files locally before exfiltration. |
| T1082 System Information Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version. |
| T1083 File and Directory Discovery |
MalwareMacMa | MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders. |
| T1095 Non-Application Layer Protocol |
MalwareMacMa | MacMa has used a custom JSON-based protocol for its C&C communications. |
| T1105 Ingress Tool Transfer |
MalwareMacMa | MacMa has downloaded additional files, including an exploit for used privilege escalation. |
| T1106 Native API |
MalwareMacMa | MacMa has used macOS API functions to perform tasks. |
| T1113 Screen Capture |
MalwareMacMa | MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows. |
| T1123 Audio Capture |
MalwareMacMa | MacMa has the ability to record audio. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMacMa | MacMa decrypts a downloaded file using AES-128-EBC with a custom delta. |
| T1543.001 Launch Agent |
MalwareMacMa | MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user. |
| T1553.001 Gatekeeper Bypass |
MalwareMacMa | MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`. |
| T1553.002 Code Signing |
MalwareMacMa | MacMa has been delivered using ad hoc Apple Developer code signing certificates. |
| T1555.001 Keychain |
MalwareMacMa | MacMa can dump credentials from the macOS keychain. |
| T1571 Non-Standard Port |
MalwareMacMa | MacMa has used TCP port 5633 for C2 Communication. |
| T1573 Encrypted Channel |
MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| T1680 Local Storage Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer's disk sizes. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareMacMa | MacMa can clear possible malware traces such as application logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.