FruitFly is designed to spy on mac users [1].
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1543 | .001 | Create or Modify System Process: Launch Agent | |
Enterprise | T1083 | File and Directory Discovery | ||
Enterprise | T1564 | .001 | Hide Artifacts: Hidden Files and Directories |
FruitFly saves itself with a leading "." to make it a hidden file.[1] |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion | |
Enterprise | T1027 | .010 | Obfuscated Files or Information: Command Obfuscation | |
Enterprise | T1057 | Process Discovery |
FruitFly has the ability to list processes on the system.[1] |
|
Enterprise | T1113 | Screen Capture |