FruitFly

S0277

Malware.View on attack.mitre.org

About this malware

FruitFly is designed to spy on mac users .

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.010
Command Obfuscation

FruitFly executes and stores obfuscated Perl scripts.

T1057
Process Discovery

FruitFly has the ability to list processes on the system.

T1070.004
File Deletion

FruitFly will delete files on the system.

T1083
File and Directory Discovery

FruitFly looks for specific files and file types.

T1113
Screen Capture

FruitFly takes screenshots of the user's desktop.

T1543.001
Launch Agent

FruitFly persists via a Launch Agent.

T1564.001
Hidden Files and Directories

FruitFly saves itself with a leading "." to make it a hidden file.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. objsee mac malware 2017 Open source
    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.