Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1027.015 Compression |
WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1036 Masquerading |
WindTail has used icons mimicking MS Office files to mask payloads. |
| T1036.001 Invalid Code Signature |
WindTail has been incompletely signed with revoked certificates. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl. |
| T1059.004 Unix Shell |
WindTail can use the |
| T1070.004 File Deletion |
WindTail has the ability to receive and execute a self-delete command. |
| T1071.001 Web Protocols |
WindTail has the ability to use HTTP for C2 communications. |
| T1083 File and Directory Discovery |
WindTail has the ability to enumerate the users home directory and the path to its own application bundle. |
| T1106 Native API |
WindTail can invoke Apple APIs |
| T1119 Automated Collection |
WindTail can identify and add files that possess specific file extensions to an array for archiving. |
| T1124 System Time Discovery |
WindTail has the ability to generate the current date and time. |
| T1140 Deobfuscate/Decode Files or Information |
WindTail has the ability to decrypt strings using hard-coded AES keys. |
| T1560.001 Archive via Utility |
WindTail has the ability to use the macOS built-in zip utility to archive files. |
| T1564.003 Hidden Window |
WindTail can instruct the OS to execute an application without a dock icon or menu. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.