ATT&CKReferencesObjectiveSee AppleJeus 2019

ObjectiveSee AppleJeus 2019

Patrick Wardle. (2019, October 12). Pass the AppleJeus. Retrieved September 28, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1071.001
Web Protocols
MalwareAppleJeus

AppleJeus has sent data to its C2 server via POST requests.

T1543.004
Launch Daemon
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1546.016
Installer Packages
MalwareAppleJeus

During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.