M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMacMa | MacMa can collect then exfiltrate files from the compromised system. |
| T1016 System Network Configuration Discovery |
MalwareMacMa | MacMa can collect IP addresses from a compromised host. |
| T1021 Remote Services |
MalwareMacMa | MacMa can manage remote screen sessions. |
| T1033 System Owner/User Discovery |
MalwareMacMa | MacMa can collect the username from the compromised machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareMacMa | MacMa exfiltrates data from a supplied path over its C2 channel. |
| T1057 Process Discovery |
MalwareMacMa | MacMa can enumerate running processes. |
| T1059.004 Unix Shell |
MalwareMacMa | MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1070.004 File Deletion |
MalwareMacMa | MacMa can delete itself from the compromised computer. |
| T1070.006 Timestomp |
MalwareMacMa | MacMa has the capability to create and modify file timestamps. |
| T1082 System Information Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version. |
| T1083 File and Directory Discovery |
MalwareMacMa | MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders. |
| T1095 Non-Application Layer Protocol |
MalwareMacMa | MacMa has used a custom JSON-based protocol for its C&C communications. |
| T1105 Ingress Tool Transfer |
MalwareMacMa | MacMa has downloaded additional files, including an exploit for used privilege escalation. |
| T1106 Native API |
MalwareMacMa | MacMa has used macOS API functions to perform tasks. |
| T1113 Screen Capture |
MalwareMacMa | MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMacMa | MacMa decrypts a downloaded file using AES-128-EBC with a custom delta. |
| T1543.001 Launch Agent |
MalwareMacMa | MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user. |
| T1553.001 Gatekeeper Bypass |
MalwareMacMa | MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`. |
| T1555.001 Keychain |
MalwareMacMa | MacMa can dump credentials from the macOS keychain. |
| T1571 Non-Standard Port |
MalwareMacMa | MacMa has used TCP port 5633 for C2 Communication. |
| T1573 Encrypted Channel |
MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| T1680 Local Storage Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer's disk sizes. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareMacMa | MacMa can clear possible malware traces such as application logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.