Malware.View on attack.mitre.org
This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor .
| Technique | Procedure example |
|---|---|
| T1036.006 Space after Filename |
Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program. |
| T1056.002 GUI Input Capture |
Keydnap prompts the users for credentials. |
| T1059.006 Python |
Keydnap uses Python for scripting to execute additional commands. |
| T1071.001 Web Protocols |
Keydnap uses HTTPS for command and control. |
| T1090.003 Multi-hop Proxy |
Keydnap uses a copy of tor2web proxy for HTTPS communications. |
| T1543.001 Launch Agent |
Keydnap uses a Launch Agent to persist. |
| T1548.001 Setuid and Setgid |
Keydnap adds the setuid flag to a binary so it can easily elevate in the future. |
| T1555.002 Securityd Memory |
Keydnap uses the keychaindump project to read securityd memory. |
| T1564.009 Resource Forking |
Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.