Dok

S0281

Malware.View on attack.mitre.org

About this malware

Dok is a Trojan application disguised as a .zip file that is able to collect user credentials and install a malicious proxy server to redirect a user's network traffic (i.e. Adversary-in-the-Middle).

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.002
Software Packing

Dok is packed with an UPX executable packer.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Dok exfiltrates logs of its execution stored in the /tmp folder over FTP using the curl command.

T1056.002
GUI Input Capture

Dok prompts the user for credentials.

T1059.002
AppleScript

Dok uses AppleScript to create a login item for persistence.

T1090.003
Multi-hop Proxy

Dok downloads and installs Tor via homebrew.

T1222.002
Linux and Mac Permissions

Dok gives all users execute permissions for the application using the command chmod +x /Users/Shared/AppStore.app.

T1543.001
Launch Agent

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

T1547.015
Login Items

Dok uses AppleScript to install a login Item by sending Apple events to the System Events process.

T1548.003
Sudo and Sudo Caching

Dok adds admin ALL=(ALL) NOPASSWD: ALL to the /etc/sudoers file.

T1553.004
Install Root Certificate

Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/filename.

T1557
Adversary-in-the-Middle

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. CheckPoint Dok Open source
    Ofer Caspi. (2017, May 4). OSX Malware is Catching Up, and it wants to Read Your HTTPS Traffic. Retrieved October 5, 2021.
  2. hexed osx.dok analysis 2019 Open source
    fluffybunny. (2019, July 9). OSX.Dok Analysis. Retrieved November 17, 2024.
  3. objsee mac malware 2017 Open source
    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.