Keydnap

S0276

Malware.View on attack.mitre.org

About this malware

This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor .

Techniques used9

Procedure examples9

TechniqueProcedure example
T1036.006
Space after Filename

Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program.

T1056.002
GUI Input Capture

Keydnap prompts the users for credentials.

T1059.006
Python

Keydnap uses Python for scripting to execute additional commands.

T1071.001
Web Protocols

Keydnap uses HTTPS for command and control.

T1090.003
Multi-hop Proxy

Keydnap uses a copy of tor2web proxy for HTTPS communications.

T1543.001
Launch Agent

Keydnap uses a Launch Agent to persist.

T1548.001
Setuid and Setgid

Keydnap adds the setuid flag to a binary so it can easily elevate in the future.

T1555.002
Securityd Memory

Keydnap uses the keychaindump project to read securityd memory.

T1564.009
Resource Forking

Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. OSX Keydnap malware Open source
    Marc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.