Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCalisto | Calisto can collect data from user directories. |
| T1016 System Network Configuration Discovery |
MalwareCalisto | Calisto runs the |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCalisto | Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac. |
| T1070.004 File Deletion |
MalwareCalisto | Calisto has the capability to use |
| T1074.001 Local Data Staging |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1217 Browser Information Discovery |
MalwareCalisto | Calisto collects information on bookmarks from Google Chrome. |
| T1543.001 Launch Agent |
MalwareCalisto | Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| T1555.001 Keychain |
MalwareCalisto | Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1560.001 Archive via Utility |
MalwareCalisto | Calisto uses the |
| T1564.001 Hidden Files and Directories |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1569.001 Launchctl |
MalwareCalisto | Calisto uses launchctl to enable screen sharing on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.