Malware.View on attack.mitre.org
FruitFly is designed to spy on mac users .
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
FruitFly executes and stores obfuscated Perl scripts. |
| T1057 Process Discovery |
FruitFly has the ability to list processes on the system. |
| T1070.004 File Deletion |
FruitFly will delete files on the system. |
| T1083 File and Directory Discovery |
FruitFly looks for specific files and file types. |
| T1113 Screen Capture |
FruitFly takes screenshots of the user's desktop. |
| T1543.001 Launch Agent |
FruitFly persists via a Launch Agent. |
| T1564.001 Hidden Files and Directories |
FruitFly saves itself with a leading "." to make it a hidden file. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.