Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareWindTail | WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1027.015 Compression |
MalwareWindTail | WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWindTail | WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl. |
| T1070.004 File Deletion |
MalwareWindTail | WindTail has the ability to receive and execute a self-delete command. |
| T1071.001 Web Protocols |
MalwareWindTail | WindTail has the ability to use HTTP for C2 communications. |
| T1083 File and Directory Discovery |
MalwareWindTail | WindTail has the ability to enumerate the users home directory and the path to its own application bundle. |
| T1106 Native API |
MalwareWindTail | WindTail can invoke Apple APIs |
| T1119 Automated Collection |
MalwareWindTail | WindTail can identify and add files that possess specific file extensions to an array for archiving. |
| T1560.001 Archive via Utility |
MalwareWindTail | WindTail has the ability to use the macOS built-in zip utility to archive files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.