Malware.View on attack.mitre.org
OSX_OCEANLOTUS.D is a macOS backdoor used by APT32. First discovered in 2015, APT32 has continued to make improvements using a plugin architecture to extend capabilities, specifically using `.dylib` files. OSX_OCEANLOTUS.D can also determine it's permission level and execute according to access type (`root` or `user`).
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
OSX_OCEANLOTUS.D has the ability to upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1027.002 Software Packing |
OSX_OCEANLOTUS.D has a variant that is packed with UPX. |
| T1027.013 Encrypted/Encoded File |
OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR. |
| T1036.004 Masquerade Task or Service |
OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login. |
| T1036.008 Masquerade File Type |
OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1059.001 PowerShell |
OSX_OCEANLOTUS.D uses PowerShell scripts. |
| T1059.004 Unix Shell |
OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1059.005 Visual Basic |
OSX_OCEANLOTUS.D uses Word macros for execution. |
| T1070.004 File Deletion |
OSX_OCEANLOTUS.D has a command to delete a file from the system. OSX_OCEANLOTUS.D deletes the app bundle and dropper after execution. |
| T1070.006 Timestomp |
OSX_OCEANLOTUS.D can use the |
| T1071.001 Web Protocols |
OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information. |
| T1082 System Information Discovery |
OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1095 Non-Application Layer Protocol |
OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic. |
| T1105 Ingress Tool Transfer |
OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.