Magisa, L. (2020, November 27). New MacOS Backdoor Connected to OceanLotus Surfaces. Retrieved December 2, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has the ability to upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1036.008 Masquerade File Type |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1070.004 File Deletion |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution. |
| T1070.006 Timestomp |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can use the |
| T1071.001 Web Protocols |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information. |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1105 Ingress Tool Transfer |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1553.001 Gatekeeper Bypass |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses the command |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.