TF-MAL-osx.macspy
📛 Threat Title
Malware family: MacSpy
Description
ThreatFox malware family `osx.macspy`. Printable name: MacSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.macspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macspy
IOC database
- Type
- domain
- Value
osx.macspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.macspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.cloudfall.cn
ID: S0282 ⓘ Type: MALWARE ⓘ Platforms: macOS Version: 1.1 Created: 17 October 2018 Last Modified: 30 March 2020 ATT&CK® Navigator Layers Techniques Used Domain ID Name Use Enterprise T1071 .001 Application Layer Protocol: Web Protocols
-
web:attack.mitre.org
MacSpy persists via a Launch Agent. [1] Enterprise T1564 .001 Hide Artifacts: Hidden Files and Directories MacSpy stores itself in ~/Library/.DS_Stores/ [2] Enterprise T1070 .004 Indicator Removal: File Deletion MacSpy deletes any temporary files it creates [2] Enterprise T1056 .001 Input Capture: Keylogging
-
web:cfoc.org
What Is Trojan.MacOS. MacSpy .A1? Trojan.MacOS. MacSpy .A1 is a Mac malware designed to infect Apple computers running macOS. Trojan.MacOS. MacSpy .A1 typically spreads through malicious websites, compromised software downloads, phishing emails, and malicious attachments. Once Trojan.MacOS. MacSpy .A1 has infected your Mac, it can cause a variety of problems, including crashing applications, slowing ...
-
web:cyber-kill-chain.ch
The cyber kill chain commentary by cyber-kill-chain.ch offers IT experts, forensic specialists and specialized legal advisors practice-oriented assessments and well-founded know-how.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:leaf-it.com
MacSpy is a sophisticated new malware targeting Apple devices, capable of logging keystrokes, recording audio, taking screenshots, and even encrypting data. Learn how this threat works and why staying vigilant is essential to protecting your system.
-
web:macos.checkpoint.com
MacSpy is Malware as a Service (MaaS). The malware authors claim that it is undetected by anti-viruses and it is offered with basic version for free, and in addition in a paid version more advanced features available such as:- File encryption (similar to Ransomware)- Access to emails- Official code signing for the malicious file- Webcam ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the MacSpy malware family including references, samples and yara signatures.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.intego.com
In June, two research teams independently discovered a new Mac malware family , dubbed JokerSpy. One of the malware's early stages includes a cross-platform component, hinting that variants of JokerSpy may also exist for Windows and Linux as well. Let's explore what you need to know about this new Mac threat and how to stay protected.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.