CallMe

S0077

Malware.View on attack.mitre.org

About this malware

CallMe is a Trojan designed to run on Apple OSX. It is based on a publicly available tool called Tiny SHell.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

CallMe exfiltrates data to its C2 server over the same protocol as C2 communications.

T1059.004
Unix Shell

CallMe has the capability to create a reverse shell on victims.

T1105
Ingress Tool Transfer

CallMe has the capability to download a file to the victim from the C2 server.

T1573.001
Symmetric Cryptography

CallMe uses AES to encrypt C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Scarlet Mimic Jan 2016 Open source
    Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.