ATT&CKReferencesobjective-see windtail2 jan 2019

objective-see windtail2 jan 2019

Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareWindTail

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1027.015
Compression
MalwareWindTail

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWindTail

WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl.

T1070.004
File Deletion
MalwareWindTail

WindTail has the ability to receive and execute a self-delete command.

T1071.001
Web Protocols
MalwareWindTail

WindTail has the ability to use HTTP for C2 communications.

T1083
File and Directory Discovery
MalwareWindTail

WindTail has the ability to enumerate the users home directory and the path to its own application bundle.

T1106
Native API
MalwareWindTail

WindTail can invoke Apple APIs contentsOfDirectoryAtPath, pathExtension, and (string) compare.

T1119
Automated Collection
MalwareWindTail

WindTail can identify and add files that possess specific file extensions to an array for archiving.

T1560.001
Archive via Utility
MalwareWindTail

WindTail has the ability to use the macOS built-in zip utility to archive files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.