Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1082 System Information Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command |
| T1083 File and Directory Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has used the command |
| T1105 Ingress Tool Transfer |
MalwareOSX/Shlayer | OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOSX/Shlayer | OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to |
| T1564 Hide Artifacts |
MalwareOSX/Shlayer | OSX/Shlayer has used the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.