TF-MAL-osx.keysteal
📛 Threat Title
Malware family: KeySteal
Description
ThreatFox malware family `osx.keysteal`. Printable name: KeySteal.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.keysteal
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keysteal
IOC database
- Type
- domain
- Value
osx.keysteal- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.keysteal
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keysteal
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login ...
-
web:bladeintel.com
KeySteal : KeySteal is a macOS infostealer initially observed in 2021 and added to XProtect in February 2023. MRTv3: This is a collection of malware detection and removal components grandfathered into XProtect from its predecessor, the Malware Removal Tool (MRT). Pirrit: This one is also not disguised for some reason.
-
web:github.com
macOS Malware Collection. Contribute to objective-see/ Malware development by creating an account on GitHub.
-
web:objective-see.org
What was the purpose of the malware ? a backdoor? a cryptocurrency miner? or something more insidious… Indicators of Compromise: What are the observable "symptoms" of the malware …including its executable components, created files/directories, and of course (if relevant) address of network endpoints such as command and control servers.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.infostealers.com
Conclusion The continued prevalence and adaptation of macOS infostealers like KeySteal , Atomic InfoStealer, and CherryPie underscores the ongoing challenges facing macOS enterprise users. Despite solid efforts by Apple to update its XProtect signature database, these rapidly evolving malware strains continue to evade.
-
web:www.microsoft.com
How modern infostealers target macOS systems, leverage Python‑based stealers, and abuse trusted platforms and utilities to distribute credential‑stealing payloads.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
What is KEYSTEAL ? KEYSTEAL is the name of a trojan targeting macOS Keychain data. This malware arrives onto systems as a trojanized app called ResignTool. Due to how sensitive the information stored on the Mac Keychain can be - this malware poses significant threats to user privacy. KEYSTEAL malware overview The variant of KEYSTEAL that we analyzed was installed by a malicious installer ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.