iKitten

S0278

Malware.View on attack.mitre.org

About this malware

iKitten is a macOS exfiltration agent .

Techniques used7

Procedure examples7

TechniqueProcedure example
T1016
System Network Configuration Discovery

iKitten will look for the current IP address.

T1037.004
RC Scripts

iKitten adds an entry to the rc.common file for persistence.

T1056.002
GUI Input Capture

iKitten prompts the user for their credentials.

T1057
Process Discovery

iKitten lists the current processes running.

T1555.001
Keychain

iKitten collects the keychains on the system.

T1560.001
Archive via Utility

iKitten will zip up the /Library/Keychains directory before exfiltrating it.

T1564.001
Hidden Files and Directories

iKitten saves itself with a leading "." so that it's hidden from users by default.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. objsee mac malware 2017 Open source
    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.