ATT&CKReferencesSofacy Komplex Trojan

Sofacy Komplex Trojan

Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

Open the source

Techniques4

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareKomplex

The OsInfo function in Komplex collects the current running username.

T1057
Process Discovery
MalwareKomplex

The OsInfo function in Komplex collects a running process list.

T1070.004
File Deletion
MalwareKomplex

The Komplex trojan supports file deletion.

T1071.001
Web Protocols
MalwareKomplex

The Komplex C2 channel uses HTTP POST requests.

T1543.001
Launch Agent
MalwareKomplex

The Komplex trojan creates a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist with launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist.

T1564.001
Hidden Files and Directories
MalwareKomplex

The Komplex payload is stored in a hidden directory at /Users/Shared/.local/kextd.

T1573.001
Symmetric Cryptography
MalwareKomplex

The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.