ATT&CKReferencesCarbon Black Shlayer Feb 2019

Carbon Black Shlayer Feb 2019

Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareOSX/Shlayer

OSX/Shlayer can masquerade as a Flash Player update.

T1059.004
Unix Shell
MalwareOSX/Shlayer

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1082
System Information Discovery
MalwareOSX/Shlayer

OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command sw_vers -productVersion.

T1105
Ingress Tool Transfer
MalwareOSX/Shlayer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1140
Deobfuscate/Decode Files or Information
MalwareOSX/Shlayer

OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to openssl and then write the payload to the /tmp folder.

T1204.002
Malicious File
MalwareOSX/Shlayer

OSX/Shlayer has relied on users mounting and executing a malicious DMG file.

T1222.002
Linux and Mac Permissions
MalwareOSX/Shlayer

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1548.004
Elevated Execution with Prompt
MalwareOSX/Shlayer

OSX/Shlayer can escalate privileges to root by asking the user for credentials.

T1553.001
Gatekeeper Bypass
MalwareOSX/Shlayer

If running with elevated privileges, OSX/Shlayer has used the spctl command to disable Gatekeeper protection for a downloaded file. OSX/Shlayer can also leverage system links pointing to bash scripts in the downloaded DMG file to bypass Gatekeeper, a flaw patched in macOS 11.3 and later versions. OSX/Shlayer has been Notarized by Apple, resulting in successful passing of additional Gatekeeper checks.

T1564.001
Hidden Files and Directories
MalwareOSX/Shlayer

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.