s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.jokerspy

📛 Threat Title

Malware family: JokerSpy

Category: JokerSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.jokerspy`. Printable name: JokerSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.jokerspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.jokerspy

IOC database

Type
domain
Value
osx.jokerspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.jokerspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.jokerspy

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag JokerSpy MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with JokerSpy . Database Entry

  • web:blog.netmanageit.com

    Description An overview of JOKERSPY , discovered in June 2023, which deployed custom and open source macOS tools to exploit a cryptocurrency exchange located in Japan.

  • web:cybersecuritynews.com

    This malware is capable of providing an active adversary deployment, a backdoor and it is a form of open-source reconnaissance. It is a multi-platform exploitable tool and is capable of macOS exploitation. JokerSpy - Multi-Stage macOS Malware The Initial phase of compromise of this malware is still being investigated.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the JokerSpy malware family including references, samples and yara signatures.

  • web:malware.news

    Key takeaways, This is an initial notification of an active intrusion with additional details to follow REF9134 leverages custom and open source tools for ...

  • web:phxtechsol.com

    JokerSpy | Unknown Adversary Targeting Organizations with Multi-Stage macOS Malware June 28, 2023 / 0 Comments / in Blog / by Phoenix Technology

  • web:qd5.com

    Due to its popularity, threat actors have begun to target macOS devices recently. Based on the recent reports from SentinelOne, Bitdefender and Elastic, a new type of macOS malware […] The post JokerSpy - Multi-Stage macOS Malware Attacking Organisation Worldwide appeared first on Cyber Security News.

  • web:www.elastic.co

    Initial research exposing JOKERSPY An overview of JOKERSPY , discovered in June 2023, which deployed custom and open source macOS tools to exploit a cryptocurrency exchange located in Japan.

  • web:www.intego.com

    In June, two research teams independently discovered a new Mac malware family , dubbed JokerSpy . One of the malware's early stages includes a cross-platform component, hinting that variants of JokerSpy may also exist for Windows and Linux as well.

  • web:www.sentinelone.com

    JokerSpy appears to be part of a larger campaign that is likely targeting more organizations than currently known. Learn how to detect it and stay protected.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.