Komplex

S0162

Malware.View on attack.mitre.org

About this malware

Komplex is a backdoor that has been used by APT28 on OS X and appears to be developed in a similar manner to XAgentOSX .

Techniques used7

Procedure examples7

TechniqueProcedure example
T1033
System Owner/User Discovery

The OsInfo function in Komplex collects the current running username.

T1057
Process Discovery

The OsInfo function in Komplex collects a running process list.

T1070.004
File Deletion

The Komplex trojan supports file deletion.

T1071.001
Web Protocols

The Komplex C2 channel uses HTTP POST requests.

T1543.001
Launch Agent

The Komplex trojan creates a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist with launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist.

T1564.001
Hidden Files and Directories

The Komplex payload is stored in a hidden directory at /Users/Shared/.local/kextd.

T1573.001
Symmetric Cryptography

The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Sofacy Komplex Trojan Open source
    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.
  2. XAgentOSX 2017 Open source
    Robert Falcone. (2017, February 14). XAgentOSX: Sofacy's Xagent macOS Tool. Retrieved July 12, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.