Horejsi, J. (2018, April 04). New MacOS Backdoor Linked to OceanLotus Found. Retrieved November 13, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1027.013 Encrypted/Encoded File |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR. |
| T1059.001 PowerShell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses PowerShell scripts. |
| T1059.005 Visual Basic |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses Word macros for execution. |
| T1070.004 File Deletion |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution. |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1105 Ingress Tool Transfer |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
| T1564.001 Hidden Files and Directories |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.