ATT&CKSoftwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D

S0352

Malware.View on attack.mitre.org

About this malware

OSX_OCEANLOTUS.D is a macOS backdoor used by APT32. First discovered in 2015, APT32 has continued to make improvements using a plugin architecture to extend capabilities, specifically using `.dylib` files. OSX_OCEANLOTUS.D can also determine it's permission level and execute according to access type (`root` or `user`).

Techniques used28

Procedure examples28

TechniqueProcedure example
T1005
Data from Local System

OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.

T1016
System Network Configuration Discovery

OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host.

T1027.002
Software Packing

OSX_OCEANLOTUS.D has a variant that is packed with UPX.

T1027.013
Encrypted/Encoded File

OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR.

T1036.004
Masquerade Task or Service

OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login.

T1036.008
Masquerade File Type

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1059.001
PowerShell

OSX_OCEANLOTUS.D uses PowerShell scripts.

T1059.004
Unix Shell

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1059.005
Visual Basic

OSX_OCEANLOTUS.D uses Word macros for execution.

T1070.004
File Deletion

OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution.

T1070.006
Timestomp

OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.

T1071.001
Web Protocols

OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information.

T1082
System Information Discovery

OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the ioreg command to gather some of this information.

T1095
Non-Application Layer Protocol

OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic.

T1105
Ingress Tool Transfer

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Trend Micro MacOS Backdoor November 2020 Open source
    Magisa, L. (2020, November 27). New MacOS Backdoor Connected to OceanLotus Surfaces. Retrieved December 2, 2020.
  2. TrendMicro MacOS April 2018 Open source
    Horejsi, J. (2018, April 04). New MacOS Backdoor Linked to OceanLotus Found. Retrieved November 13, 2018.
  3. Unit42 OceanLotus 2017 Open source
    Erye Hernandez and Danny Tsechansky. (2017, June 22). The New and Improved macOS Backdoor from OceanLotus. Retrieved September 8, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.