ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1016×

27 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMacMa

MacMa can collect then exfiltrate files from the compromised system.

T1016
System Network Configuration Discovery
MalwareMacMa

MacMa can collect IP addresses from a compromised host.

T1021
Remote Services
MalwareMacMa

MacMa can manage remote screen sessions.

T1033
System Owner/User Discovery
MalwareMacMa

MacMa can collect the username from the compromised machine.

T1041
Exfiltration Over C2 Channel
MalwareMacMa

MacMa exfiltrates data from a supplied path over its C2 channel.

T1056.001
Keylogging
MalwareMacMa

MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords.

T1057
Process Discovery
MalwareMacMa

MacMa can enumerate running processes.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1070.004
File Deletion
MalwareMacMa

MacMa can delete itself from the compromised computer.

T1070.006
Timestomp
MalwareMacMa

MacMa has the capability to create and modify file timestamps.

T1074.001
Local Data Staging
MalwareMacMa

MacMa has stored collected files locally before exfiltration.

T1082
System Information Discovery
MalwareMacMa

MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version.

T1083
File and Directory Discovery
MalwareMacMa

MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders.

T1095
Non-Application Layer Protocol
MalwareMacMa

MacMa has used a custom JSON-based protocol for its C&C communications.

T1105
Ingress Tool Transfer
MalwareMacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.

T1106
Native API
MalwareMacMa

MacMa has used macOS API functions to perform tasks.

T1113
Screen Capture
MalwareMacMa

MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows.

T1123
Audio Capture
MalwareMacMa

MacMa has the ability to record audio.

T1140
Deobfuscate/Decode Files or Information
MalwareMacMa

MacMa decrypts a downloaded file using AES-128-EBC with a custom delta.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

T1553.001
Gatekeeper Bypass
MalwareMacMa

MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`.

T1553.002
Code Signing
MalwareMacMa

MacMa has been delivered using ad hoc Apple Developer code signing certificates.

T1555.001
Keychain
MalwareMacMa

MacMa can dump credentials from the macOS keychain.

T1571
Non-Standard Port
MalwareMacMa

MacMa has used TCP port 5633 for C2 Communication.

T1573
Encrypted Channel
MalwareMacMa

MacMa has used TLS encryption to initialize a custom protocol for C2 communications.

T1680
Local Storage Discovery
MalwareMacMa

MacMa can collect information about a compromised computer's disk sizes.

T1685.006
Clear Linux or Mac System Logs
MalwareMacMa

MacMa can clear possible malware traces such as application logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.