S0466macOS

S0466WindTail

Platforms
1
ATT&CK
14.1
References
4

Description

[WindTail](https://attack.mitre.org/software/S0466) is a macOS surveillance implant used by [Windshift](https://attack.mitre.org/groups/G0112). [WindTail](https://attack.mitre.org/software/S0466) shares code similarities with Hack Back aka KitM OSX.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)

Platforms· 1

macOS

Attributed to1

TypeTargetConfidenceTier
GroupWindshiftg011295%live

References

  1. https://attack.mitre.org/software/S0466
  2. https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1554718868.pdf
  3. https://objective-see.com/blog/blog_0x3B.html
  4. https://objective-see.com/blog/blog_0x3D.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
iKitten
Software
WINDSHIELD
Software
MoonWind
Software
XCSSET
Software
Anchor
Software
MacMa
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.