Register to stream ATT&CKcon 2.0 October 29-30


iKitten is a macOS exfiltration agent [1].

ID: S0278
Associated Software: OSX/MacDownloader
Platforms: macOS
Version: 1.0

Associated Software Descriptions

Name Description
OSX/MacDownloader [1].

Techniques Used

Domain ID Name Use
Enterprise T1002 Data Compressed iKitten will zip up the /Library/Keychains directory before exfiltrating it. [1]
Enterprise T1158 Hidden Files and Directories iKitten saves itself with a leading "." so that it's hidden from users by default. [1]
Enterprise T1141 Input Prompt iKitten prompts the user for their credentials. [1]
Enterprise T1142 Keychain iKitten collects the keychains on the system. [1]
Enterprise T1057 Process Discovery iKitten lists the current processes running. [1]
Enterprise T1163 Rc.common iKitten adds an entry to the rc.common file for persistence. [1]
Enterprise T1016 System Network Configuration Discovery iKitten will look for the current IP address. [1]