Thomas Reed. (2018, October 29). Mac cryptocurrency ticker app installs backdoors. Retrieved April 23, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareCoinTicker | CoinTicker initially downloads a hidden encoded file. |
| T1059.003 Windows Command Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.004 Unix Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.006 Python |
MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| T1105 Ingress Tool Transfer |
MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCoinTicker | CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL. |
| T1543.001 Launch Agent |
MalwareCoinTicker | CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| T1553.001 Gatekeeper Bypass |
MalwareCoinTicker | CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag. |
| T1564.001 Hidden Files and Directories |
MalwareCoinTicker | CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string]. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.