Bundlore

S0482

Malware.View on attack.mitre.org

About this malware

Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1027
Obfuscated Files or Information

Bundlore has obfuscated data with base64, AES, RC4, and bz2.

T1036.005
Match Legitimate Resource Name or Location

Bundlore has disguised a malicious .app file as a Flash Player update.

T1048
Exfiltration Over Alternative Protocol

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

T1056.002
GUI Input Capture

Bundlore prompts the user for their credentials.

T1057
Process Discovery

Bundlore has used the ps command to list processes.

T1059.002
AppleScript

Bundlore can use AppleScript to inject malicious JavaScript into a browser.

T1059.004
Unix Shell

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.006
Python

Bundlore has used Python scripts to execute payloads.

T1059.007
JavaScript

Bundlore can execute JavaScript by injecting it into the victim's browser.

T1071.001
Web Protocols

Bundlore uses HTTP requests for C2.

T1082
System Information Discovery

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1098.004
SSH Authorized Keys

Bundlore creates a new key pair with ssh-keygen and drops the newly created user key in authorized_keys to enable remote login.

T1105
Ingress Tool Transfer

Bundlore can download and execute new versions of itself.

T1140
Deobfuscate/Decode Files or Information

Bundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.

T1176.001
Browser Extensions

Bundlore can install malicious browser extensions that are used to hijack user searches.

View all 23 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. MacKeeper Bundlore Apr 2019 Open source
    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.