Patrick Wardle. (2017, January 1). Mac Malware of 2016. Retrieved September 21, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.006 Space after Filename |
MalwareKeydnap | Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program. |
| T1056.002 GUI Input Capture |
MalwareKeydnap | Keydnap prompts the users for credentials. |
| T1059.006 Python |
MalwareKeydnap | Keydnap uses Python for scripting to execute additional commands. |
| T1071.001 Web Protocols |
MalwareKeydnap | Keydnap uses HTTPS for command and control. |
| T1090.003 Multi-hop Proxy |
MalwareKeydnap | Keydnap uses a copy of tor2web proxy for HTTPS communications. |
| T1543.001 Launch Agent |
MalwareKeydnap | Keydnap uses a Launch Agent to persist. |
| T1555.002 Securityd Memory |
MalwareKeydnap | Keydnap uses the keychaindump project to read securityd memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.