ATT&CKReferencesESET DazzleSpy Jan 2022

ESET DazzleSpy Jan 2022

M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMacMa

MacMa can collect then exfiltrate files from the compromised system.

T1016
System Network Configuration Discovery
MalwareMacMa

MacMa can collect IP addresses from a compromised host.

T1021
Remote Services
MalwareMacMa

MacMa can manage remote screen sessions.

T1033
System Owner/User Discovery
MalwareMacMa

MacMa can collect the username from the compromised machine.

T1041
Exfiltration Over C2 Channel
MalwareMacMa

MacMa exfiltrates data from a supplied path over its C2 channel.

T1057
Process Discovery
MalwareMacMa

MacMa can enumerate running processes.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1070.004
File Deletion
MalwareMacMa

MacMa can delete itself from the compromised computer.

T1070.006
Timestomp
MalwareMacMa

MacMa has the capability to create and modify file timestamps.

T1082
System Information Discovery
MalwareMacMa

MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version.

T1083
File and Directory Discovery
MalwareMacMa

MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders.

T1095
Non-Application Layer Protocol
MalwareMacMa

MacMa has used a custom JSON-based protocol for its C&C communications.

T1105
Ingress Tool Transfer
MalwareMacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.

T1106
Native API
MalwareMacMa

MacMa has used macOS API functions to perform tasks.

T1113
Screen Capture
MalwareMacMa

MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows.

T1140
Deobfuscate/Decode Files or Information
MalwareMacMa

MacMa decrypts a downloaded file using AES-128-EBC with a custom delta.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

T1553.001
Gatekeeper Bypass
MalwareMacMa

MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`.

T1555.001
Keychain
MalwareMacMa

MacMa can dump credentials from the macOS keychain.

T1571
Non-Standard Port
MalwareMacMa

MacMa has used TCP port 5633 for C2 Communication.

T1573
Encrypted Channel
MalwareMacMa

MacMa has used TLS encryption to initialize a custom protocol for C2 communications.

T1680
Local Storage Discovery
MalwareMacMa

MacMa can collect information about a compromised computer's disk sizes.

T1685.006
Clear Linux or Mac System Logs
MalwareMacMa

MacMa can clear possible malware traces such as application logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.