ATT&CKReferencesCheckPoint Dok

CheckPoint Dok

Ofer Caspi. (2017, May 4). OSX Malware is Catching Up, and it wants to Read Your HTTPS Traffic. Retrieved October 5, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1222.002
Linux and Mac Permissions
MalwareDok

Dok gives all users execute permissions for the application using the command chmod +x /Users/Shared/AppStore.app.

T1543.001
Launch Agent
MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

T1557
Adversary-in-the-Middle
MalwareDok

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.