Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1553.001 Gatekeeper Bypass |
MalwareOSX/Shlayer | If running with elevated privileges, OSX/Shlayer has used the |
| T1564 Hide Artifacts |
MalwareOSX/Shlayer | OSX/Shlayer has used the |
| T1564.011 Ignore Process Interrupts |
MalwareOSX/Shlayer | OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.