Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOSX/Shlayer | OSX/Shlayer can masquerade as a Flash Player update. |
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1082 System Information Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command |
| T1105 Ingress Tool Transfer |
MalwareOSX/Shlayer | OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX/Shlayer | OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to |
| T1204.002 Malicious File |
MalwareOSX/Shlayer | OSX/Shlayer has relied on users mounting and executing a malicious DMG file. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1548.004 Elevated Execution with Prompt |
MalwareOSX/Shlayer | OSX/Shlayer can escalate privileges to root by asking the user for credentials. |
| T1553.001 Gatekeeper Bypass |
MalwareOSX/Shlayer | If running with elevated privileges, OSX/Shlayer has used the |
| T1564.001 Hidden Files and Directories |
MalwareOSX/Shlayer | OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.