Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThiefQuest | ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable. |
| T1041 Exfiltration Over C2 Channel |
MalwareThiefQuest | ThiefQuest exfiltrates targeted file extensions in the |
| T1071.001 Web Protocols |
MalwareThiefQuest | ThiefQuest uploads files via unencrypted HTTP. |
| T1554 Compromise Host Software Binary |
MalwareThiefQuest | ThiefQuest searches through the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.