Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.004 Launch Daemon |
MalwareCOATHANGER | COATHANGER will create a daemon for timed check-ins with command and control infrastructure. |
| T1543.004 Launch Daemon |
MalwareDacls | Dacls can establish persistence via a Launch Daemon. |
| T1543.004 Launch Daemon |
MalwareREPTILE | The REPTILE launcher can daemonize a process. |
| T1543.004 Launch Daemon |
MalwareGreen Lambert | Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence. |
| T1543.004 Launch Daemon |
MalwareThiefQuest | When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the |
| T1543.004 Launch Daemon |
MalwareBundlore | Bundlore can persist via a LaunchDaemon. |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
| T1543.004 Launch Daemon |
MalwareXCSSET | XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim. |
| T1543.004 Launch Daemon |
MalwareAppleJeus | AppleJeus has placed a plist file within the |
| T1543.004 Launch Daemon |
MalwareLoudMiner | LoudMiner adds plist files with the naming format |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.