Marc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1548.001 Setuid and Setgid |
MalwareKeydnap | Keydnap adds the setuid flag to a binary so it can easily elevate in the future. |
| T1564.009 Resource Forking |
MalwareKeydnap | Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.