ATT&CKReferencesESET OceanLotus macOS April 2019

ESET OceanLotus macOS April 2019

Dumont, R.. (2019, April 9). OceanLotus: macOS malware update. Retrieved April 15, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a variant that is packed with UPX.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1070.004
File Deletion
GroupAPT32

APT32's macOS backdoor can receive a “delete” command.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1082
System Information Discovery
GroupAPT32

APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.

T1222.002
Linux and Mac Permissions
GroupAPT32

APT32's macOS backdoor changes the permission of the file it wants to execute to 755.

T1497.001
System Checks
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time.

T1564.001
Hidden Files and Directories
GroupAPT32

APT32's macOS backdoor hides the clientID file via a chflags function.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.