Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareBundlore | Bundlore has obfuscated data with base64, AES, RC4, and bz2. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBundlore | Bundlore has disguised a malicious .app file as a Flash Player update. |
| T1056.002 GUI Input Capture |
MalwareBundlore | Bundlore prompts the user for their credentials. |
| T1057 Process Discovery |
MalwareBundlore | Bundlore has used the |
| T1059.002 AppleScript |
MalwareBundlore | Bundlore can use AppleScript to inject malicious JavaScript into a browser. |
| T1059.004 Unix Shell |
MalwareBundlore | Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| T1059.006 Python |
MalwareBundlore | Bundlore has used Python scripts to execute payloads. |
| T1059.007 JavaScript |
MalwareBundlore | Bundlore can execute JavaScript by injecting it into the victim's browser. |
| T1071.001 Web Protocols |
MalwareBundlore | Bundlore uses HTTP requests for C2. |
| T1082 System Information Discovery |
MalwareBundlore | Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using |
| T1098.004 SSH Authorized Keys |
MalwareBundlore | Bundlore creates a new key pair with |
| T1105 Ingress Tool Transfer |
MalwareBundlore | Bundlore can download and execute new versions of itself. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBundlore | Bundlore has used |
| T1176.001 Browser Extensions |
MalwareBundlore | Bundlore can install malicious browser extensions that are used to hijack user searches. |
| T1189 Drive-by Compromise |
MalwareBundlore | Bundlore has been spread through malicious advertisements on websites. |
| T1204.002 Malicious File |
MalwareBundlore | Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update. |
| T1518 Software Discovery |
MalwareBundlore | Bundlore has the ability to enumerate what browser is being used as well as version information for Safari. |
| T1543.001 Launch Agent |
MalwareBundlore | Bundlore can persist via a LaunchAgent. |
| T1543.004 Launch Daemon |
MalwareBundlore | Bundlore can persist via a LaunchDaemon. |
| T1685 Disable or Modify Tools |
MalwareBundlore | Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.