Description
[XAgentOSX](https://attack.mitre.org/software/S0161) is a trojan that has been used by [APT28](https://attack.mitre.org/groups/G0007) on OS X and appears to be a port of their standard [CHOPSTICK](https://attack.mitre.org/software/S0023) or XAgent trojan. (Citation: XAgentOSX 2017)
External References
Techniques Used by This Malware
- T1033 — System Owner/User Discovery
- T1056.001 — Keylogging
- T1057 — Process Discovery
- T1070.004 — File Deletion
- T1071.002 — File Transfer Protocols
- T1082 — System Information Discovery
- T1083 — File and Directory Discovery
- T1106 — Native API
- T1113 — Screen Capture
- T1555.003 — Credentials from Web Browsers