Threat report

www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware

https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
Published on
www.welivesecurity.com

ATT&CK techniques those detections carry

  • T1543Create or Modify System Process
  • T1543.001Launch Agent
  • T1543.004Launch Daemon
  • T1547Boot or Logon Autostart Execution
  • T1547.011Plist Modification
  • T1564Hide Artifacts
  • T1564.001Hidden Files and Directories
Open the original

3 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Launch Item Registration with Suspicious Executable Path via macOS Security EventsMedium
Persistence via a Hidden Plist Filename via macOS Security EventsMedium
Persistence via a Hidden Plist FilenameHigh

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice