iKitten is a macOS exfiltration agent [1].

ID: S0278
Associated Software: OSX/MacDownloader
Platforms: macOS
Version: 1.0

Associated Software Descriptions

Name Description
OSX/MacDownloader [1].

Techniques Used

Domain ID Name Use
Enterprise T1002 Data Compressed iKitten will zip up the /Library/Keychains directory before exfiltrating it.[1]
Enterprise T1158 Hidden Files and Directories iKitten saves itself with a leading "." so that it's hidden from users by default.[1]
Enterprise T1141 Input Prompt iKitten prompts the user for their credentials.[1]
Enterprise T1142 Keychain iKitten collects the keychains on the system.[1]
Enterprise T1057 Process Discovery iKitten lists the current processes running.[1]
Enterprise T1163 Rc.common iKitten adds an entry to the rc.common file for persistence.[1]
Enterprise T1016 System Network Configuration Discovery iKitten will look for the current IP address.[1]