Janicab

S0163

Malware.View on attack.mitre.org

About this malware

Janicab is an OS X trojan that relied on a valid developer ID and oblivious users to install it.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1053.003
Cron

Janicab used a cron job for persistence on Mac devices.

T1113
Screen Capture

Janicab captured screenshots and sent them out to a C2 server.

T1123
Audio Capture

Janicab captured audio and sent it out to a C2 server.

T1553.002
Code Signing

Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Janicab Open source
    Thomas. (2013, July 15). New signed malware called Janicab. Retrieved July 17, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.