Phil Stokes. (2020, December 2). APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique. Retrieved September 13, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1222.002 Linux and Mac Permissions |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.