Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.002 GUI Input Capture |
MalwareCalisto | Calisto presents an input prompt asking for the user's login and password. |
| T1074.001 Local Data Staging |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1098 Account Manipulation |
MalwareCalisto | Calisto adds permissions and remote logins to all users. |
| T1105 Ingress Tool Transfer |
MalwareCalisto | Calisto has the capability to upload and download files to the victim's machine. |
| T1136.001 Local Account |
MalwareCalisto | Calisto has the capability to add its own account to the victim's machine. |
| T1555.001 Keychain |
MalwareCalisto | Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1560.001 Archive via Utility |
MalwareCalisto | Calisto uses the |
| T1564.001 Hidden Files and Directories |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.