MacSpy

S0282

Malware.View on attack.mitre.org

About this malware

MacSpy is a malware-as-a-service offered on the darkweb .

Techniques used9

Procedure examples9

TechniqueProcedure example
T1056.001
Keylogging

MacSpy captures keystrokes.

T1070.004
File Deletion

MacSpy deletes any temporary files it creates

T1071.001
Web Protocols

MacSpy uses HTTP for command and control.

T1090.003
Multi-hop Proxy

MacSpy uses Tor for command and control.

T1113
Screen Capture

MacSpy can capture screenshots of the desktop over multiple monitors.

T1115
Clipboard Data

MacSpy can steal clipboard contents.

T1123
Audio Capture

MacSpy can record the sounds from microphones on a computer.

T1543.001
Launch Agent

MacSpy persists via a Launch Agent.

T1564.001
Hidden Files and Directories

MacSpy stores itself in ~/Library/.DS_Stores/

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. objsee mac malware 2017 Open source
    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.