THREAT OPS › Threat News › Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-51de75d4-db3f-4d94-81f4-ec6741ca52db"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Archive via UtilityT1560.001
- KeychainT1555.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- AppleScriptT1059.002
- Data from Local SystemT1005
- Deobfuscate/Decode Files or InformationT1140
- Credentials from Password StoresT1555
- Social EngineeringT1684
- Unsecured CredentialsT1552
- Archive Collected DataT1560
- Credentials from Web BrowsersT1555.003
- Command and Scripting InterpreterT1059
- Automated ExfiltrationT1020
- Indicator RemovalT1070
- Credentials In FilesT1552.001
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- Chat MessagesT1552.008
- Unix ShellT1059.004
- Social MediaT1593.001
- CredentialsT1589.001
- Data Transfer Size LimitsT1030
- File DeletionT1070.004
- Web ProtocolsT1071.001
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- CompressionT1027.015
- Data from Local SystemAML.T0037
- Command and Scripting InterpreterAML.T0050
- Unsecured CredentialsAML.T0055
- Process DiscoveryAML.T0089
Indicators of compromise
- https://www.rstcloud.com/macsync-stealer-c2-infrastructure-rotation/url
- https://ss64.com/mac/osascript.htmlurl
- https://microsoft.github.io/zerotrustassessment/url