Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Bundlore has obfuscated data with base64, AES, RC4, and bz2. |
| T1036.005 Match Legitimate Resource Name or Location |
Bundlore has disguised a malicious .app file as a Flash Player update. |
| T1048 Exfiltration Over Alternative Protocol |
Bundlore uses the |
| T1056.002 GUI Input Capture |
Bundlore prompts the user for their credentials. |
| T1057 Process Discovery |
Bundlore has used the |
| T1059.002 AppleScript |
Bundlore can use AppleScript to inject malicious JavaScript into a browser. |
| T1059.004 Unix Shell |
Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| T1059.006 Python |
Bundlore has used Python scripts to execute payloads. |
| T1059.007 JavaScript |
Bundlore can execute JavaScript by injecting it into the victim's browser. |
| T1071.001 Web Protocols |
Bundlore uses HTTP requests for C2. |
| T1082 System Information Discovery |
Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using |
| T1098.004 SSH Authorized Keys |
Bundlore creates a new key pair with |
| T1105 Ingress Tool Transfer |
Bundlore can download and execute new versions of itself. |
| T1140 Deobfuscate/Decode Files or Information |
Bundlore has used |
| T1176.001 Browser Extensions |
Bundlore can install malicious browser extensions that are used to hijack user searches. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.