Malware.View on attack.mitre.org
OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
OSX/Shlayer can masquerade as a Flash Player update. |
| T1059.004 Unix Shell |
OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1082 System Information Discovery |
OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command |
| T1083 File and Directory Discovery |
OSX/Shlayer has used the command |
| T1105 Ingress Tool Transfer |
OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1140 Deobfuscate/Decode Files or Information |
OSX/Shlayer can base64-decode and AES-decrypt downloaded payloads. Versions of OSX/Shlayer pass encrypted and password-protected code to |
| T1176.001 Browser Extensions |
OSX/Shlayer can install malicious Safari browser extensions to serve ads. |
| T1204.002 Malicious File |
OSX/Shlayer has relied on users mounting and executing a malicious DMG file. |
| T1222.002 Linux and Mac Permissions |
OSX/Shlayer can use the |
| T1548.004 Elevated Execution with Prompt |
OSX/Shlayer can escalate privileges to root by asking the user for credentials. |
| T1553.001 Gatekeeper Bypass |
If running with elevated privileges, OSX/Shlayer has used the |
| T1564 Hide Artifacts |
OSX/Shlayer has used the |
| T1564.001 Hidden Files and Directories |
OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG. |
| T1564.009 Resource Forking |
OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners. |
| T1564.011 Ignore Process Interrupts |
OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.