Proton

S0279

Malware.View on attack.mitre.org

About this malware

Proton is a macOS backdoor focusing on data theft and credential access .

Techniques used15

Procedure examples15

TechniqueProcedure example
T1021.005
VNC

Proton uses VNC to connect into systems.

T1056.001
Keylogging

Proton uses a keylogger to capture keystrokes.

T1056.002
GUI Input Capture

Proton prompts users for their credentials.

T1059.004
Unix Shell

Proton uses macOS' .command file type to script actions.

T1070.004
File Deletion

Proton removes all files in the /tmp directory.

T1113
Screen Capture

Proton captures the content of the desktop with the screencapture binary.

T1140
Deobfuscate/Decode Files or Information

Proton uses an encrypted file to store commands and configuration values.

T1543.001
Launch Agent

Proton persists via Launch Agent.

T1548.003
Sudo and Sudo Caching

Proton modifies the tty_tickets line in the sudoers file.

T1555.001
Keychain

Proton gathers credentials in files for keychains.

T1555.003
Credentials from Web Browsers

Proton gathers credentials for Google Chrome.

T1555.005
Password Managers

Proton gathers credentials in files for 1password.

T1560
Archive Collected Data

Proton zips up files before exfiltrating them.

T1685
Disable or Modify Tools

Proton kills security tools like Wireshark that are running.

T1685.006
Clear Linux or Mac System Logs

Proton removes logs from /var/logs and /Library/logs.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. objsee mac malware 2017 Open source
    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.