Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareiKitten | iKitten will look for the current IP address. |
| T1021.005 VNC |
MalwareProton | Proton uses VNC to connect into systems. |
| T1027.010 Command Obfuscation |
MalwareFruitFly | FruitFly executes and stores obfuscated Perl scripts. |
| T1037.004 RC Scripts |
MalwareiKitten | iKitten adds an entry to the rc.common file for persistence. |
| T1056.001 Keylogging |
MalwareMacSpy | MacSpy captures keystrokes. |
| T1056.001 Keylogging |
MalwareProton | Proton uses a keylogger to capture keystrokes. |
| T1056.002 GUI Input Capture |
MalwareProton | Proton prompts users for their credentials. |
| T1056.002 GUI Input Capture |
MalwareDok | Dok prompts the user for credentials. |
| T1056.002 GUI Input Capture |
MalwareiKitten | iKitten prompts the user for their credentials. |
| T1057 Process Discovery |
MalwareFruitFly | FruitFly has the ability to list processes on the system. |
| T1057 Process Discovery |
MalwareiKitten | iKitten lists the current processes running. |
| T1059.002 AppleScript |
MalwareDok | Dok uses AppleScript to create a login item for persistence. |
| T1059.004 Unix Shell |
MalwareProton | Proton uses macOS' .command file type to script actions. |
| T1070.004 File Deletion |
MalwareFruitFly | FruitFly will delete files on the system. |
| T1070.004 File Deletion |
MalwareProton | Proton removes all files in the /tmp directory. |
| T1071.001 Web Protocols |
MalwareMacSpy | MacSpy uses HTTP for command and control. |
| T1083 File and Directory Discovery |
MalwareFruitFly | FruitFly looks for specific files and file types. |
| T1090.003 Multi-hop Proxy |
MalwareMacSpy | |
| T1090.003 Multi-hop Proxy |
MalwareDok | |
| T1113 Screen Capture |
MalwareProton | Proton captures the content of the desktop with the screencapture binary. |
| T1113 Screen Capture |
MalwareMacSpy | MacSpy can capture screenshots of the desktop over multiple monitors. |
| T1113 Screen Capture |
MalwareFruitFly | FruitFly takes screenshots of the user's desktop. |
| T1115 Clipboard Data |
MalwareMacSpy | MacSpy can steal clipboard contents. |
| T1123 Audio Capture |
MalwareMacSpy | MacSpy can record the sounds from microphones on a computer. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareProton | Proton uses an encrypted file to store commands and configuration values. |
| T1543.001 Launch Agent |
MalwareFruitFly | FruitFly persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareDok | Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
| T1543.001 Launch Agent |
MalwareMacSpy | MacSpy persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareProton | Proton persists via Launch Agent. |
| T1548.003 Sudo and Sudo Caching |
MalwareProton | Proton modifies the tty_tickets line in the sudoers file. |
| T1553.004 Install Root Certificate |
MalwareDok | Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command |
| T1555.001 Keychain |
MalwareProton | Proton gathers credentials in files for keychains. |
| T1555.001 Keychain |
MalwareiKitten | iKitten collects the keychains on the system. |
| T1555.003 Credentials from Web Browsers |
MalwareProton | Proton gathers credentials for Google Chrome. |
| T1555.005 Password Managers |
MalwareProton | Proton gathers credentials in files for 1password. |
| T1557 Adversary-in-the-Middle |
MalwareDok | Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic. |
| T1560 Archive Collected Data |
MalwareProton | Proton zips up files before exfiltrating them. |
| T1560.001 Archive via Utility |
MalwareiKitten | iKitten will zip up the /Library/Keychains directory before exfiltrating it. |
| T1564.001 Hidden Files and Directories |
MalwareiKitten | iKitten saves itself with a leading "." so that it's hidden from users by default. |
| T1564.001 Hidden Files and Directories |
MalwareFruitFly | FruitFly saves itself with a leading "." to make it a hidden file. |
| T1685 Disable or Modify Tools |
MalwareProton | Proton kills security tools like Wireshark that are running. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareProton | Proton removes logs from |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.