ATT&CKSoftwareCoinTicker

CoinTicker

S0369

Malware.View on attack.mitre.org

About this malware

CoinTicker is a malicious application that poses as a cryptocurrency price ticker and installs components of the open source backdoors EvilOSX and EggShell.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027
Obfuscated Files or Information

CoinTicker initially downloads a hidden encoded file.

T1059.003
Windows Command Shell

CoinTicker executes a bash script to establish a reverse shell.

T1059.004
Unix Shell

CoinTicker executes a bash script to establish a reverse shell.

T1059.006
Python

CoinTicker executes a Python script to download its second stage.

T1105
Ingress Tool Transfer

CoinTicker executes a Python script to download its second stage.

T1140
Deobfuscate/Decode Files or Information

CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL.

T1543.001
Launch Agent

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

T1553.001
Gatekeeper Bypass

CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag.

T1564.001
Hidden Files and Directories

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. CoinTicker 2019 Open source
    Thomas Reed. (2018, October 29). Mac cryptocurrency ticker app installs backdoors. Retrieved April 23, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.