Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Calisto can collect data from user directories. |
| T1016 System Network Configuration Discovery |
Calisto runs the |
| T1036.005 Match Legitimate Resource Name or Location |
Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac. |
| T1056.002 GUI Input Capture |
Calisto presents an input prompt asking for the user's login and password. |
| T1070.004 File Deletion |
Calisto has the capability to use |
| T1074.001 Local Data Staging |
Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1098 Account Manipulation |
Calisto adds permissions and remote logins to all users. |
| T1105 Ingress Tool Transfer |
Calisto has the capability to upload and download files to the victim's machine. |
| T1136.001 Local Account |
Calisto has the capability to add its own account to the victim's machine. |
| T1217 Browser Information Discovery |
Calisto collects information on bookmarks from Google Chrome. |
| T1543.001 Launch Agent |
Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| T1555.001 Keychain |
Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1560.001 Archive via Utility |
Calisto uses the |
| T1564.001 Hidden Files and Directories |
Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1569.001 Launchctl |
Calisto uses launchctl to enable screen sharing on the victim’s machine. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.