ATT&CKReferencesMacKeeper Bundlore Apr 2019

MacKeeper Bundlore Apr 2019

Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBundlore

Bundlore has obfuscated data with base64, AES, RC4, and bz2.

T1036.005
Match Legitimate Resource Name or Location
MalwareBundlore

Bundlore has disguised a malicious .app file as a Flash Player update.

T1056.002
GUI Input Capture
MalwareBundlore

Bundlore prompts the user for their credentials.

T1057
Process Discovery
MalwareBundlore

Bundlore has used the ps command to list processes.

T1059.002
AppleScript
MalwareBundlore

Bundlore can use AppleScript to inject malicious JavaScript into a browser.

T1059.004
Unix Shell
MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.006
Python
MalwareBundlore

Bundlore has used Python scripts to execute payloads.

T1059.007
JavaScript
MalwareBundlore

Bundlore can execute JavaScript by injecting it into the victim's browser.

T1071.001
Web Protocols
MalwareBundlore

Bundlore uses HTTP requests for C2.

T1082
System Information Discovery
MalwareBundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1098.004
SSH Authorized Keys
MalwareBundlore

Bundlore creates a new key pair with ssh-keygen and drops the newly created user key in authorized_keys to enable remote login.

T1105
Ingress Tool Transfer
MalwareBundlore

Bundlore can download and execute new versions of itself.

T1140
Deobfuscate/Decode Files or Information
MalwareBundlore

Bundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.

T1176.001
Browser Extensions
MalwareBundlore

Bundlore can install malicious browser extensions that are used to hijack user searches.

T1189
Drive-by Compromise
MalwareBundlore

Bundlore has been spread through malicious advertisements on websites.

T1204.002
Malicious File
MalwareBundlore

Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update.

T1518
Software Discovery
MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

T1543.001
Launch Agent
MalwareBundlore

Bundlore can persist via a LaunchAgent.

T1543.004
Launch Daemon
MalwareBundlore

Bundlore can persist via a LaunchDaemon.

T1685
Disable or Modify Tools
MalwareBundlore

Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the pkill cfprefsd command to prevent users from inspecting processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.