ATT&CKReferencesTrendMicro macOS Dacls May 2020

TrendMicro macOS Dacls May 2020

Mabutas, G. (2020, May 11). New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability. Retrieved August 10, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1027.013
Encrypted/Encoded File
MalwareDacls

Dacls can encrypt its configuration file with AES CBC.

T1057
Process Discovery
MalwareDacls

Dacls can collect data on running and parent processes.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1071.001
Web Protocols
MalwareDacls

Dacls can use HTTPS in C2 communications.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1083
File and Directory Discovery
MalwareDacls

Dacls can scan directories on a compromised host.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1105
Ingress Tool Transfer
MalwareDacls

Dacls can download its payload from a C2 server.

T1543.001
Launch Agent
MalwareDacls

Dacls can establish persistence via a LaunchAgent.

T1543.004
Launch Daemon
MalwareDacls

Dacls can establish persistence via a Launch Daemon.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1564.001
Hidden Files and Directories
MalwareDacls

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.