ATT&CKReferencesTrend Micro MacOS Backdoor November 2020

Trend Micro MacOS Backdoor November 2020

Magisa, L. (2020, November 27). New MacOS Backdoor Connected to OceanLotus Surfaces. Retrieved December 2, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.

T1016
System Network Configuration Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host.

T1036.008
Masquerade File Type
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1059.004
Unix Shell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1070.004
File Deletion
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution.

T1070.006
Timestomp
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1071.001
Web Protocols
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information.

T1082
System Information Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the ioreg command to gather some of this information.

T1105
Ingress Tool Transfer
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.

T1543.001
Launch Agent
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchAgents.

T1553.001
Gatekeeper Bypass
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses the command xattr -d com.apple.quarantine to remove the quarantine file attribute used by Gatekeeper.

T1560.002
Archive via Library
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.