Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
GroupWindshift | Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1036 Masquerading |
MalwareWindTail | WindTail has used icons mimicking MS Office files to mask payloads. |
| T1036.001 Invalid Code Signature |
GroupWindshift | Windshift has used revoked certificates to sign malware. |
| T1036.001 Invalid Code Signature |
MalwareWindTail | WindTail has been incompletely signed with revoked certificates. |
| T1059.004 Unix Shell |
MalwareWindTail | WindTail can use the |
| T1083 File and Directory Discovery |
MalwareWindTail | WindTail has the ability to enumerate the users home directory and the path to its own application bundle. |
| T1124 System Time Discovery |
MalwareWindTail | WindTail has the ability to generate the current date and time. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWindTail | WindTail has the ability to decrypt strings using hard-coded AES keys. |
| T1189 Drive-by Compromise |
GroupWindshift | Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1564.003 Hidden Window |
MalwareWindTail | WindTail can instruct the OS to execute an application without a dock icon or menu. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.