Malware.View on attack.mitre.org
Dok is a Trojan application disguised as a .zip file that is able to collect user credentials and install a malicious proxy server to redirect a user's network traffic (i.e. Adversary-in-the-Middle).
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Dok is packed with an UPX executable packer. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Dok exfiltrates logs of its execution stored in the |
| T1056.002 GUI Input Capture |
Dok prompts the user for credentials. |
| T1059.002 AppleScript |
Dok uses AppleScript to create a login item for persistence. |
| T1090.003 Multi-hop Proxy |
|
| T1222.002 Linux and Mac Permissions |
Dok gives all users execute permissions for the application using the command |
| T1543.001 Launch Agent |
Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
| T1547.015 Login Items |
Dok uses AppleScript to install a login Item by sending Apple events to the |
| T1548.003 Sudo and Sudo Caching |
Dok adds |
| T1553.004 Install Root Certificate |
Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command |
| T1557 Adversary-in-the-Middle |
Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.