MacMa

S1016

Malware.View on attack.mitre.org

About this malware

MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021. MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1005
Data from Local System

MacMa can collect then exfiltrate files from the compromised system.

T1016
System Network Configuration Discovery

MacMa can collect IP addresses from a compromised host.

T1021
Remote Services

MacMa can manage remote screen sessions.

T1033
System Owner/User Discovery

MacMa can collect the username from the compromised machine.

T1041
Exfiltration Over C2 Channel

MacMa exfiltrates data from a supplied path over its C2 channel.

T1056.001
Keylogging

MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords.

T1057
Process Discovery

MacMa can enumerate running processes.

T1059.004
Unix Shell

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1070.004
File Deletion

MacMa can delete itself from the compromised computer.

T1070.006
Timestomp

MacMa has the capability to create and modify file timestamps.

T1074.001
Local Data Staging

MacMa has stored collected files locally before exfiltration.

T1082
System Information Discovery

MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version.

T1083
File and Directory Discovery

MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders.

T1095
Non-Application Layer Protocol

MacMa has used a custom JSON-based protocol for its C&C communications.

T1105
Ingress Tool Transfer

MacMa has downloaded additional files, including an exploit for used privilege escalation.

View all 27 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET DazzleSpy Jan 2022 Open source
    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.
  2. Symantec Daggerfly 2024 Open source
    Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.