Malware.View on attack.mitre.org
CoinTicker is a malicious application that poses as a cryptocurrency price ticker and installs components of the open source backdoors EvilOSX and EggShell.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
CoinTicker initially downloads a hidden encoded file. |
| T1059.003 Windows Command Shell |
CoinTicker executes a bash script to establish a reverse shell. |
| T1059.004 Unix Shell |
CoinTicker executes a bash script to establish a reverse shell. |
| T1059.006 Python |
CoinTicker executes a Python script to download its second stage. |
| T1105 Ingress Tool Transfer |
CoinTicker executes a Python script to download its second stage. |
| T1140 Deobfuscate/Decode Files or Information |
CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL. |
| T1543.001 Launch Agent |
CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| T1553.001 Gatekeeper Bypass |
CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag. |
| T1564.001 Hidden Files and Directories |
CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string]. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.