ATT&CKReferencessynack 2016 review

synack 2016 review

Patrick Wardle. (2017, January 1). Mac Malware of 2016. Retrieved September 21, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1036.006
Space after Filename
MalwareKeydnap

Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program.

T1056.002
GUI Input Capture
MalwareKeydnap

Keydnap prompts the users for credentials.

T1059.006
Python
MalwareKeydnap

Keydnap uses Python for scripting to execute additional commands.

T1071.001
Web Protocols
MalwareKeydnap

Keydnap uses HTTPS for command and control.

T1090.003
Multi-hop Proxy
MalwareKeydnap

Keydnap uses a copy of tor2web proxy for HTTPS communications.

T1543.001
Launch Agent
MalwareKeydnap

Keydnap uses a Launch Agent to persist.

T1555.002
Securityd Memory
MalwareKeydnap

Keydnap uses the keychaindump project to read securityd memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.