s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.windtail

📛 Threat Title

Malware family: WindTail

Category: WindTail First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.windtail`. Printable name: WindTail.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.windtail VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.windtail

IOC database

Type
domain
Value
osx.windtail
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.windtail

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.windtail

References (1)

Remediations (9)

  • web:attack.mitre.org

    WindTail is a macOS surveillance implant used by Windshift. WindTail shares code similarities with Hack Back aka KitM OSX. [1] [2] [3]

  • web:cve.nohackme.com

    WindTail is a macOS surveillance implant used by Windshift. WindTail shares code similarities with Hack Back aka KitM OSX. Platforms : macOS Version : 1.1 Created : 04 June 2020 Last Modified : 10 April 2024

  • web:github.com

    WindTail is a malware developed and delivered by the WindShift APT group and mostly targets government agencies and companies in the Middle East. WindShift will infect a user with WindTail by using a spear phishing emails, either by attachment or linking to crafted webpage that will exploit a vulnerability in the system to install the malware . As described by Taha Karim research "The Trails of ...

  • web:macos.checkpoint.com

    WindTail is a malware developed and delivered by the WindShift APT group and mostly targets government agencies and companies in the Middle East. WindShift will infect a user with WindTail by using a spear phishing emails, either by attachment or linking to crafted webpage that will exploit a vulnerability in the system to install the malware .

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the WindTail malware family including references, samples and yara signatures.

  • web:objective-see.org

    I've shared various OSX. WindTail samples (password: infect3d) …don't infect yourself! In this blog post, we'll analyze the WindShift APT group's 1 st -stage macOS implant: OSX. WindTail (likely variant A) Specifically we'll detail the malware's : initial infection vector method of persistence capabilities detection and removal ...

  • web:redteam.y-security.de

    Attack Simulations show realistic attacks against a company. In our Penetration Tests we perform security assessments against defined systems. In our Security Trainings we transfer our experience to your team.

  • web:www.jamf.com

    Want to play along? I've shared various OSX. WindTail samples (password: infect3d) …don't infect yourself! In this blog post, we'll analyze the WindShift APT group's 1st-stage macOS implant: OSX. WindTail (likely variant A) Specifically we'll detail the malware's : initial infection vector method of persistence capabilities detection and removal Background A few months ago, Taha ...

  • web:www.virusbulletin.com

    In this paper, we'll comprehensively dissect one such tool, OSX. WindTail .A, the fi rst-stage macOS implant utilized by the WINDSHIFT APT group (which targeted individuals of a Middle-Eastern government). After analysing the malware's unique infection vector, we'll discuss its method of persistence and its capabilities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.