Malware.View on attack.mitre.org
Janicab is an OS X trojan that relied on a valid developer ID and oblivious users to install it.
| Technique | Procedure example |
|---|---|
| T1053.003 Cron |
Janicab used a cron job for persistence on Mac devices. |
| T1113 Screen Capture |
Janicab captured screenshots and sent them out to a C2 server. |
| T1123 Audio Capture |
Janicab captured audio and sent it out to a C2 server. |
| T1553.002 Code Signing |
Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.