ATT&CKReferencesCoinTicker 2019

CoinTicker 2019

Thomas Reed. (2018, October 29). Mac cryptocurrency ticker app installs backdoors. Retrieved April 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareCoinTicker

CoinTicker initially downloads a hidden encoded file.

T1059.003
Windows Command Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.004
Unix Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.006
Python
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1105
Ingress Tool Transfer
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1140
Deobfuscate/Decode Files or Information
MalwareCoinTicker

CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL.

T1543.001
Launch Agent
MalwareCoinTicker

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

T1553.001
Gatekeeper Bypass
MalwareCoinTicker

CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag.

T1564.001
Hidden Files and Directories
MalwareCoinTicker

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.