Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCryptoistic | Cryptoistic can retrieve files from the local file system. |
| T1033 System Owner/User Discovery |
MalwareCryptoistic | Cryptoistic can gather data on the user of a compromised host. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1036 Masquerading |
MalwareDacls | The Dacls Mach-O binary has been disguised as a .nib file. |
| T1070.004 File Deletion |
MalwareCryptoistic | Cryptoistic has the ability delete files from a compromised host. |
| T1071.001 Web Protocols |
MalwareDacls | Dacls can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1083 File and Directory Discovery |
MalwareCryptoistic | Cryptoistic can scan a directory to identify files for deletion. |
| T1095 Non-Application Layer Protocol |
MalwareCryptoistic | Cryptoistic can use TCP in communications with C2. |
| T1105 Ingress Tool Transfer |
MalwareDacls | Dacls can download its payload from a C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCryptoistic | Cryptoistic has the ability to send and receive files. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1543.001 Launch Agent |
MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| T1543.004 Launch Daemon |
MalwareDacls | Dacls can establish persistence via a Launch Daemon. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1564.001 Hidden Files and Directories |
MalwareDacls | Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
| T1573 Encrypted Channel |
MalwareCryptoistic | Cryptoistic can engage in encrypted communications with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.