ATT&CKReferencesobjsee mac malware 2017

objsee mac malware 2017

Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software5

Campaigns0

None recorded.

Procedure examples42

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareiKitten

iKitten will look for the current IP address.

T1021.005
VNC
MalwareProton

Proton uses VNC to connect into systems.

T1027.010
Command Obfuscation
MalwareFruitFly

FruitFly executes and stores obfuscated Perl scripts.

T1037.004
RC Scripts
MalwareiKitten

iKitten adds an entry to the rc.common file for persistence.

T1056.001
Keylogging
MalwareMacSpy

MacSpy captures keystrokes.

T1056.001
Keylogging
MalwareProton

Proton uses a keylogger to capture keystrokes.

T1056.002
GUI Input Capture
MalwareProton

Proton prompts users for their credentials.

T1056.002
GUI Input Capture
MalwareDok

Dok prompts the user for credentials.

T1056.002
GUI Input Capture
MalwareiKitten

iKitten prompts the user for their credentials.

T1057
Process Discovery
MalwareFruitFly

FruitFly has the ability to list processes on the system.

T1057
Process Discovery
MalwareiKitten

iKitten lists the current processes running.

T1059.002
AppleScript
MalwareDok

Dok uses AppleScript to create a login item for persistence.

T1059.004
Unix Shell
MalwareProton

Proton uses macOS' .command file type to script actions.

T1070.004
File Deletion
MalwareFruitFly

FruitFly will delete files on the system.

T1070.004
File Deletion
MalwareProton

Proton removes all files in the /tmp directory.

T1071.001
Web Protocols
MalwareMacSpy

MacSpy uses HTTP for command and control.

T1083
File and Directory Discovery
MalwareFruitFly

FruitFly looks for specific files and file types.

T1090.003
Multi-hop Proxy
MalwareMacSpy

MacSpy uses Tor for command and control.

T1090.003
Multi-hop Proxy
MalwareDok

Dok downloads and installs Tor via homebrew.

T1113
Screen Capture
MalwareProton

Proton captures the content of the desktop with the screencapture binary.

T1113
Screen Capture
MalwareMacSpy

MacSpy can capture screenshots of the desktop over multiple monitors.

T1113
Screen Capture
MalwareFruitFly

FruitFly takes screenshots of the user's desktop.

T1115
Clipboard Data
MalwareMacSpy

MacSpy can steal clipboard contents.

T1123
Audio Capture
MalwareMacSpy

MacSpy can record the sounds from microphones on a computer.

T1140
Deobfuscate/Decode Files or Information
MalwareProton

Proton uses an encrypted file to store commands and configuration values.

T1543.001
Launch Agent
MalwareFruitFly

FruitFly persists via a Launch Agent.

T1543.001
Launch Agent
MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

T1543.001
Launch Agent
MalwareMacSpy

MacSpy persists via a Launch Agent.

T1543.001
Launch Agent
MalwareProton

Proton persists via Launch Agent.

T1548.003
Sudo and Sudo Caching
MalwareProton

Proton modifies the tty_tickets line in the sudoers file.

T1553.004
Install Root Certificate
MalwareDok

Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/filename.

T1555.001
Keychain
MalwareProton

Proton gathers credentials in files for keychains.

T1555.001
Keychain
MalwareiKitten

iKitten collects the keychains on the system.

T1555.003
Credentials from Web Browsers
MalwareProton

Proton gathers credentials for Google Chrome.

T1555.005
Password Managers
MalwareProton

Proton gathers credentials in files for 1password.

T1557
Adversary-in-the-Middle
MalwareDok

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

T1560
Archive Collected Data
MalwareProton

Proton zips up files before exfiltrating them.

T1560.001
Archive via Utility
MalwareiKitten

iKitten will zip up the /Library/Keychains directory before exfiltrating it.

T1564.001
Hidden Files and Directories
MalwareiKitten

iKitten saves itself with a leading "." so that it's hidden from users by default.

T1564.001
Hidden Files and Directories
MalwareFruitFly

FruitFly saves itself with a leading "." to make it a hidden file.

T1685
Disable or Modify Tools
MalwareProton

Proton kills security tools like Wireshark that are running.

T1685.006
Clear Linux or Mac System Logs
MalwareProton

Proton removes logs from /var/logs and /Library/logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.