Proton
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1548 | .003 | Abuse Elevation Control Mechanism: Sudo and Sudo Caching |
Proton modifies the tty_tickets line in the sudoers file.(Citation: objsee mac malware 2017) |
Enterprise | T1059 | .004 | Command and Scripting Interpreter: Unix Shell |
Proton uses macOS' .command file type to script actions.(Citation: objsee mac malware 2017) |
Enterprise | T1543 | .001 | Create or Modify System Process: Launch Agent |
Proton persists via Launch Agent.(Citation: objsee mac malware 2017) |
Enterprise | T1555 | .001 | Credentials from Password Stores: Keychain |
Proton gathers credentials in files for keychains.(Citation: objsee mac malware 2017) |
.003 | Credentials from Password Stores: Credentials from Web Browsers |
Proton gathers credentials for Google Chrome.(Citation: objsee mac malware 2017) |
||
.005 | Credentials from Password Stores: Password Managers |
Proton gathers credentials in files for 1password.(Citation: objsee mac malware 2017) |
||
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
Proton kills security tools like Wireshark that are running.(Citation: objsee mac malware 2017) |
Enterprise | T1070 | .002 | Indicator Removal: Clear Linux or Mac System Logs |
Proton removes logs from |
.004 | Indicator Removal: File Deletion |
Proton removes all files in the /tmp directory.(Citation: objsee mac malware 2017) |
||
Enterprise | T1056 | .001 | Input Capture: Keylogging |
Proton uses a keylogger to capture keystrokes.(Citation: objsee mac malware 2017) |
.002 | Input Capture: GUI Input Capture |
Proton prompts users for their credentials.(Citation: objsee mac malware 2017) |
||
Enterprise | T1021 | .005 | Remote Services: VNC |
Proton uses VNC to connect into systems.(Citation: objsee mac malware 2017) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.