ATT&CKSoftwareCryptoistic

Cryptoistic

S0498

Malware.View on attack.mitre.org

About this malware

Cryptoistic is a backdoor, written in Swift, that has been used by Lazarus Group.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1005
Data from Local System

Cryptoistic can retrieve files from the local file system.

T1033
System Owner/User Discovery

Cryptoistic can gather data on the user of a compromised host.

T1070.004
File Deletion

Cryptoistic has the ability delete files from a compromised host.

T1083
File and Directory Discovery

Cryptoistic can scan a directory to identify files for deletion.

T1095
Non-Application Layer Protocol

Cryptoistic can use TCP in communications with C2.

T1105
Ingress Tool Transfer

Cryptoistic has the ability to send and receive files.

T1573
Encrypted Channel

Cryptoistic can engage in encrypted communications with C2.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelOne Lazarus macOS July 2020 Open source
    Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.