Calisto

S0274

Malware.View on attack.mitre.org

About this malware

Calisto is a macOS Trojan that opens a backdoor on the compromised machine. Calisto is believed to have first been developed in 2016.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Calisto can collect data from user directories.

T1016
System Network Configuration Discovery

Calisto runs the ifconfig command to obtain the IP address from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location

Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.

T1056.002
GUI Input Capture

Calisto presents an input prompt asking for the user's login and password.

T1070.004
File Deletion

Calisto has the capability to use rm -rf to remove folders and files from the victim's machine.

T1074.001
Local Data Staging

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1098
Account Manipulation

Calisto adds permissions and remote logins to all users.

T1105
Ingress Tool Transfer

Calisto has the capability to upload and download files to the victim's machine.

T1136.001
Local Account

Calisto has the capability to add its own account to the victim's machine.

T1217
Browser Information Discovery

Calisto collects information on bookmarks from Google Chrome.

T1543.001
Launch Agent

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

T1555.001
Keychain

Calisto collects Keychain storage data and copies those passwords/tokens to a file.

T1560.001
Archive via Utility

Calisto uses the zip -r command to compress the data collected on the local system.

T1564.001
Hidden Files and Directories

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1569.001
Launchctl

Calisto uses launchctl to enable screen sharing on the victim’s machine.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Securelist Calisto July 2018 Open source
    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.
  2. Symantec Calisto July 2018 Open source
    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.