Mabutas, G. (2020, May 11). New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability. Retrieved August 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1027.013 Encrypted/Encoded File |
MalwareDacls | Dacls can encrypt its configuration file with AES CBC. |
| T1057 Process Discovery |
MalwareDacls | Dacls can collect data on running and parent processes. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1071.001 Web Protocols |
MalwareDacls | Dacls can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1083 File and Directory Discovery |
MalwareDacls | Dacls can scan directories on a compromised host. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDacls | Dacls can download its payload from a C2 server. |
| T1543.001 Launch Agent |
MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| T1543.004 Launch Daemon |
MalwareDacls | Dacls can establish persistence via a Launch Daemon. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1564.001 Hidden Files and Directories |
MalwareDacls | Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.