Malware.View on attack.mitre.org
MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021. MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
MacMa can collect then exfiltrate files from the compromised system. |
| T1016 System Network Configuration Discovery |
MacMa can collect IP addresses from a compromised host. |
| T1021 Remote Services |
MacMa can manage remote screen sessions. |
| T1033 System Owner/User Discovery |
MacMa can collect the username from the compromised machine. |
| T1041 Exfiltration Over C2 Channel |
MacMa exfiltrates data from a supplied path over its C2 channel. |
| T1056.001 Keylogging |
MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords. |
| T1057 Process Discovery |
MacMa can enumerate running processes. |
| T1059.004 Unix Shell |
MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1070.004 File Deletion |
MacMa can delete itself from the compromised computer. |
| T1070.006 Timestomp |
MacMa has the capability to create and modify file timestamps. |
| T1074.001 Local Data Staging |
MacMa has stored collected files locally before exfiltration. |
| T1082 System Information Discovery |
MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version. |
| T1083 File and Directory Discovery |
MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders. |
| T1095 Non-Application Layer Protocol |
MacMa has used a custom JSON-based protocol for its C&C communications. |
| T1105 Ingress Tool Transfer |
MacMa has downloaded additional files, including an exploit for used privilege escalation. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.