ATT&CKReferences20 macOS Common Tools and Techniques

20 macOS Common Tools and Techniques

Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

Open the source

Techniques6

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1048
Exfiltration Over Alternative Protocol
MalwareBundlore

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

T1059.004
Unix Shell
MalwareOSX/Shlayer

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1070.006
Timestomp
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1082
System Information Discovery
MalwareBundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1082
System Information Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the ioreg command to gather some of this information.

T1083
File and Directory Discovery
MalwareOSX/Shlayer

OSX/Shlayer has used the command appDir="$(dirname $(dirname "$currentDir"))" and $(dirname "$(pwd -P)") to construct installation paths.

T1105
Ingress Tool Transfer
MalwareOSX/Shlayer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1140
Deobfuscate/Decode Files or Information
MalwareOSX/Shlayer

OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to openssl and then write the payload to the /tmp folder.

T1222.002
Linux and Mac Permissions
MalwareOSX/Shlayer

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1222.002
Linux and Mac Permissions
MalwareXCSSET

XCSSET uses the chmod +x command to grant executable permissions to the malicious file.

T1222.002
Linux and Mac Permissions
MalwareBundlore

Bundlore changes the permissions of a payload using the command chmod -R 755.

T1497.001
System Checks
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time.

T1553.001
Gatekeeper Bypass
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses the command xattr -d com.apple.quarantine to remove the quarantine file attribute used by Gatekeeper.

T1564
Hide Artifacts
MalwareBundlore

Bundlore uses the mktemp utility to make unique file and directory names for payloads, such as TMP_DIR=`mktemp -d -t x.

T1564
Hide Artifacts
MalwareOSX/Shlayer

OSX/Shlayer has used the mktemp utility to make random and unique filenames for payloads, such as export tmpDir="$(mktemp -d /tmp/XXXXXXXXXXXX)" or mktemp -t Installer.

T1685
Disable or Modify Tools
MalwareBundlore

Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the pkill cfprefsd command to prevent users from inspecting processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.