The sub-techniques beta is now live! Read the release blog post for more info.


iKitten is a macOS exfiltration agent [1].

ID: S0278
Associated Software: OSX/MacDownloader
Platforms: macOS
Version: 1.0
Created: 17 October 2018
Last Modified: 17 October 2018

Associated Software Descriptions

Name Description
OSX/MacDownloader [1].

Techniques Used

Domain ID Name Use
Enterprise T1002 Data Compressed

iKitten will zip up the /Library/Keychains directory before exfiltrating it.[1]

Enterprise T1158 Hidden Files and Directories

iKitten saves itself with a leading "." so that it's hidden from users by default.[1]

Enterprise T1141 Input Prompt

iKitten prompts the user for their credentials.[1]

Enterprise T1142 Keychain

iKitten collects the keychains on the system.[1]

Enterprise T1057 Process Discovery

iKitten lists the current processes running.[1]

Enterprise T1163 Rc.common

iKitten adds an entry to the rc.common file for persistence.[1]

Enterprise T1016 System Network Configuration Discovery

iKitten will look for the current IP address.[1]