Patrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareThiefQuest | ThiefQuest obtains a list of running processes using the function |
| T1059.002 AppleScript |
MalwareThiefQuest | ThiefQuest uses AppleScript's |
| T1497.003 Time Based Checks |
MalwareThiefQuest | ThiefQuest invokes |
| T1518.001 Security Software Discovery |
MalwareThiefQuest | ThiefQuest uses the |
| T1543.001 Launch Agent |
MalwareThiefQuest | ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the |
| T1543.004 Launch Daemon |
MalwareThiefQuest | When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the |
| T1564.001 Hidden Files and Directories |
MalwareThiefQuest | ThiefQuest hides a copy of itself in the user's |
| T1685 Disable or Modify Tools |
MalwareThiefQuest | ThiefQuest uses the function |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.