ATT&CKReferencesSecurelist Calisto July 2018

Securelist Calisto July 2018

Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCalisto

Calisto can collect data from user directories.

T1016
System Network Configuration Discovery
MalwareCalisto

Calisto runs the ifconfig command to obtain the IP address from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareCalisto

Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.

T1070.004
File Deletion
MalwareCalisto

Calisto has the capability to use rm -rf to remove folders and files from the victim's machine.

T1074.001
Local Data Staging
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1217
Browser Information Discovery
MalwareCalisto

Calisto collects information on bookmarks from Google Chrome.

T1543.001
Launch Agent
MalwareCalisto

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

T1555.001
Keychain
MalwareCalisto

Calisto collects Keychain storage data and copies those passwords/tokens to a file.

T1560.001
Archive via Utility
MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

T1564.001
Hidden Files and Directories
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1569.001
Launchctl
MalwareCalisto

Calisto uses launchctl to enable screen sharing on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.