s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.keysteal

📛 Threat Title

Malware family: KeySteal

Category: KeySteal First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.keysteal`. Printable name: KeySteal.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.keysteal VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keysteal

IOC database

Type
domain
Value
osx.keysteal
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.keysteal

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keysteal

References (1)

Remediations (10)

  • web:attack.mitre.org

    Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login ...

  • web:bladeintel.com

    KeySteal : KeySteal is a macOS infostealer initially observed in 2021 and added to XProtect in February 2023. MRTv3: This is a collection of malware detection and removal components grandfathered into XProtect from its predecessor, the Malware Removal Tool (MRT). Pirrit: This one is also not disguised for some reason.

  • web:github.com

    macOS Malware Collection. Contribute to objective-see/ Malware development by creating an account on GitHub.

  • web:objective-see.org

    What was the purpose of the malware ? a backdoor? a cryptocurrency miner? or something more insidious… Indicators of Compromise: What are the observable "symptoms" of the malware …including its executable components, created files/directories, and of course (if relevant) address of network endpoints such as command and control servers.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infostealers.com

    Conclusion The continued prevalence and adaptation of macOS infostealers like KeySteal , Atomic InfoStealer, and CherryPie underscores the ongoing challenges facing macOS enterprise users. Despite solid efforts by Apple to update its XProtect signature database, these rapidly evolving malware strains continue to evade.

  • web:www.microsoft.com

    How modern infostealers target macOS systems, leverage Python‑based stealers, and abuse trusted platforms and utilities to distribute credential‑stealing payloads.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    What is KEYSTEAL ? KEYSTEAL is the name of a trojan targeting macOS Keychain data. This malware arrives onto systems as a trojanized app called ResignTool. Due to how sensitive the information stored on the Mac Keychain can be - this malware poses significant threats to user privacy. KEYSTEAL malware overview The variant of KEYSTEAL that we analyzed was installed by a malicious installer ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.