ATT&CKReferencesObjective-See MacMa Nov 2021

Objective-See MacMa Nov 2021

Wardle, P. (2021, November 11). OSX.CDDS (OSX.MacMa). Retrieved June 30, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareMacMa

MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1074.001
Local Data Staging
MalwareMacMa

MacMa has stored collected files locally before exfiltration.

T1105
Ingress Tool Transfer
MalwareMacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.

T1106
Native API
MalwareMacMa

MacMa has used macOS API functions to perform tasks.

T1113
Screen Capture
MalwareMacMa

MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows.

T1123
Audio Capture
MalwareMacMa

MacMa has the ability to record audio.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.