ATT&CKReferencesobjective-see windtail1 dec 2018

objective-see windtail1 dec 2018

Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1036
Masquerading
GroupWindshift

Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers.

T1036
Masquerading
MalwareWindTail

WindTail has used icons mimicking MS Office files to mask payloads.

T1036.001
Invalid Code Signature
GroupWindshift

Windshift has used revoked certificates to sign malware.

T1036.001
Invalid Code Signature
MalwareWindTail

WindTail has been incompletely signed with revoked certificates.

T1059.004
Unix Shell
MalwareWindTail

WindTail can use the open command to execute an application.

T1083
File and Directory Discovery
MalwareWindTail

WindTail has the ability to enumerate the users home directory and the path to its own application bundle.

T1124
System Time Discovery
MalwareWindTail

WindTail has the ability to generate the current date and time.

T1140
Deobfuscate/Decode Files or Information
MalwareWindTail

WindTail has the ability to decrypt strings using hard-coded AES keys.

T1189
Drive-by Compromise
GroupWindshift

Windshift has used compromised websites to register custom URL schemes on a remote system.

T1564.003
Hidden Window
MalwareWindTail

WindTail can instruct the OS to execute an application without a dock icon or menu.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.