ATT&CKReferencesSentinelOne Lazarus macOS July 2020

SentinelOne Lazarus macOS July 2020

Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCryptoistic

Cryptoistic can retrieve files from the local file system.

T1033
System Owner/User Discovery
MalwareCryptoistic

Cryptoistic can gather data on the user of a compromised host.

T1033
System Owner/User Discovery
GroupLazarus Group

Various Lazarus Group malware enumerates logged-on users.

T1036
Masquerading
MalwareDacls

The Dacls Mach-O binary has been disguised as a .nib file.

T1070.004
File Deletion
MalwareCryptoistic

Cryptoistic has the ability delete files from a compromised host.

T1071.001
Web Protocols
MalwareDacls

Dacls can use HTTPS in C2 communications.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1083
File and Directory Discovery
MalwareCryptoistic

Cryptoistic can scan a directory to identify files for deletion.

T1095
Non-Application Layer Protocol
MalwareCryptoistic

Cryptoistic can use TCP in communications with C2.

T1105
Ingress Tool Transfer
MalwareDacls

Dacls can download its payload from a C2 server.

T1105
Ingress Tool Transfer
MalwareCryptoistic

Cryptoistic has the ability to send and receive files.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1543.001
Launch Agent
MalwareDacls

Dacls can establish persistence via a LaunchAgent.

T1543.004
Launch Daemon
MalwareDacls

Dacls can establish persistence via a Launch Daemon.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1564.001
Hidden Files and Directories
MalwareDacls

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

T1573
Encrypted Channel
MalwareCryptoistic

Cryptoistic can engage in encrypted communications with C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.