ATT&CKReferencesSymantec Calisto July 2018

Symantec Calisto July 2018

Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1056.002
GUI Input Capture
MalwareCalisto

Calisto presents an input prompt asking for the user's login and password.

T1074.001
Local Data Staging
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1098
Account Manipulation
MalwareCalisto

Calisto adds permissions and remote logins to all users.

T1105
Ingress Tool Transfer
MalwareCalisto

Calisto has the capability to upload and download files to the victim's machine.

T1136.001
Local Account
MalwareCalisto

Calisto has the capability to add its own account to the victim's machine.

T1555.001
Keychain
MalwareCalisto

Calisto collects Keychain storage data and copies those passwords/tokens to a file.

T1560.001
Archive via Utility
MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

T1564.001
Hidden Files and Directories
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.