Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1048 Exfiltration Over Alternative Protocol |
MalwareBundlore | Bundlore uses the |
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1070.006 Timestomp |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can use the |
| T1082 System Information Discovery |
MalwareBundlore | Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1083 File and Directory Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has used the command |
| T1105 Ingress Tool Transfer |
MalwareOSX/Shlayer | OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX/Shlayer | OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to |
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1222.002 Linux and Mac Permissions |
MalwareXCSSET | XCSSET uses the |
| T1222.002 Linux and Mac Permissions |
MalwareBundlore | Bundlore changes the permissions of a payload using the command |
| T1497.001 System Checks |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time. |
| T1553.001 Gatekeeper Bypass |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses the command |
| T1564 Hide Artifacts |
MalwareBundlore | Bundlore uses the |
| T1564 Hide Artifacts |
MalwareOSX/Shlayer | OSX/Shlayer has used the |
| T1685 Disable or Modify Tools |
MalwareBundlore | Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.