WindTail

S0466

Malware.View on attack.mitre.org

About this malware

WindTail is a macOS surveillance implant used by Windshift. WindTail shares code similarities with Hack Back aka KitM OSX.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1027.015
Compression

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1036
Masquerading

WindTail has used icons mimicking MS Office files to mask payloads.

T1036.001
Invalid Code Signature

WindTail has been incompletely signed with revoked certificates.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl.

T1059.004
Unix Shell

WindTail can use the open command to execute an application.

T1070.004
File Deletion

WindTail has the ability to receive and execute a self-delete command.

T1071.001
Web Protocols

WindTail has the ability to use HTTP for C2 communications.

T1083
File and Directory Discovery

WindTail has the ability to enumerate the users home directory and the path to its own application bundle.

T1106
Native API

WindTail can invoke Apple APIs contentsOfDirectoryAtPath, pathExtension, and (string) compare.

T1119
Automated Collection

WindTail can identify and add files that possess specific file extensions to an array for archiving.

T1124
System Time Discovery

WindTail has the ability to generate the current date and time.

T1140
Deobfuscate/Decode Files or Information

WindTail has the ability to decrypt strings using hard-coded AES keys.

T1560.001
Archive via Utility

WindTail has the ability to use the macOS built-in zip utility to archive files.

T1564.003
Hidden Window

WindTail can instruct the OS to execute an application without a dock icon or menu.

Groups that use it1

Campaigns0

None recorded.

References3

  1. SANS Windshift August 2018 Open source
    Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024.
  2. objective-see windtail1 dec 2018 Open source
    Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019.
  3. objective-see windtail2 jan 2019 Open source
    Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.