TF-MAL-osx.windtail
📛 Threat Title
Malware family: WindTail
Description
ThreatFox malware family `osx.windtail`. Printable name: WindTail.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.windtail
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.windtail
IOC database
- Type
- domain
- Value
osx.windtail- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.windtail
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.windtail
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:attack.mitre.org
WindTail is a macOS surveillance implant used by Windshift. WindTail shares code similarities with Hack Back aka KitM OSX. [1] [2] [3]
-
web:cve.nohackme.com
WindTail is a macOS surveillance implant used by Windshift. WindTail shares code similarities with Hack Back aka KitM OSX. Platforms : macOS Version : 1.1 Created : 04 June 2020 Last Modified : 10 April 2024
-
web:github.com
WindTail is a malware developed and delivered by the WindShift APT group and mostly targets government agencies and companies in the Middle East. WindShift will infect a user with WindTail by using a spear phishing emails, either by attachment or linking to crafted webpage that will exploit a vulnerability in the system to install the malware . As described by Taha Karim research "The Trails of ...
-
web:macos.checkpoint.com
WindTail is a malware developed and delivered by the WindShift APT group and mostly targets government agencies and companies in the Middle East. WindShift will infect a user with WindTail by using a spear phishing emails, either by attachment or linking to crafted webpage that will exploit a vulnerability in the system to install the malware .
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the WindTail malware family including references, samples and yara signatures.
-
web:objective-see.org
I've shared various OSX. WindTail samples (password: infect3d) …don't infect yourself! In this blog post, we'll analyze the WindShift APT group's 1 st -stage macOS implant: OSX. WindTail (likely variant A) Specifically we'll detail the malware's : initial infection vector method of persistence capabilities detection and removal ...
-
web:redteam.y-security.de
Attack Simulations show realistic attacks against a company. In our Penetration Tests we perform security assessments against defined systems. In our Security Trainings we transfer our experience to your team.
-
web:www.jamf.com
Want to play along? I've shared various OSX. WindTail samples (password: infect3d) …don't infect yourself! In this blog post, we'll analyze the WindShift APT group's 1st-stage macOS implant: OSX. WindTail (likely variant A) Specifically we'll detail the malware's : initial infection vector method of persistence capabilities detection and removal Background A few months ago, Taha ...
-
web:www.virusbulletin.com
In this paper, we'll comprehensively dissect one such tool, OSX. WindTail .A, the fi rst-stage macOS implant utilized by the WINDSHIFT APT group (which targeted individuals of a Middle-Eastern government). After analysing the malware's unique infection vector, we'll discuss its method of persistence and its capabilities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.