ATT&CKReferencesOSX Keydnap malware

OSX Keydnap malware

Marc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.

Open the source

Techniques5

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1548.001
Setuid and Setgid
MalwareKeydnap

Keydnap adds the setuid flag to a binary so it can easily elevate in the future.

T1564.009
Resource Forking
MalwareKeydnap

Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.