Cryptoistic

Cryptoistic is a backdoor, written in Swift, that has been used by Lazarus Group.[1]

ID: S0498
Type: MALWARE
Platforms: macOS
Version: 1.0
Created: 10 August 2020
Last Modified: 18 August 2020

Techniques Used

Domain ID Name Use
Enterprise T1005 从本地系统获取数据

Cryptoistic can retrieve files from the local file system.[1]

Enterprise T1573 加密通道

Cryptoistic can engage in encrypted communications with C2.[1]

Enterprise T1083 文件和目录发现

Cryptoistic can scan a directory to identify files for deletion.[1]

Enterprise T1070 .004 移除指标: File Deletion

Cryptoistic has the ability delete files from a compromised host.[1]

Enterprise T1033 系统所有者/用户发现

Cryptoistic can gather data on the user of a compromised host.[1]

Enterprise T1105 输入工具传输

Cryptoistic has the ability to send and receive files.[1]

Enterprise T1095 非应用层协议

Cryptoistic can use TCP in communications with C2.[1]

Groups That Use This Software

ID Name References
G0032 Lazarus Group

[1]

References