s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.macspy

📛 Threat Title

Malware family: MacSpy

Category: MacSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.macspy`. Printable name: MacSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.macspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macspy

IOC database

Type
domain
Value
osx.macspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.macspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.macspy

References (1)

Remediations (10)

  • web:attack.cloudfall.cn

    ID: S0282 ⓘ Type: MALWARE ⓘ Platforms: macOS Version: 1.1 Created: 17 October 2018 Last Modified: 30 March 2020 ATT&CK® Navigator Layers Techniques Used Domain ID Name Use Enterprise T1071 .001 Application Layer Protocol: Web Protocols

  • web:attack.mitre.org

    MacSpy persists via a Launch Agent. [1] Enterprise T1564 .001 Hide Artifacts: Hidden Files and Directories MacSpy stores itself in ~/Library/.DS_Stores/ [2] Enterprise T1070 .004 Indicator Removal: File Deletion MacSpy deletes any temporary files it creates [2] Enterprise T1056 .001 Input Capture: Keylogging

  • web:cfoc.org

    What Is Trojan.MacOS. MacSpy .A1? Trojan.MacOS. MacSpy .A1 is a Mac malware designed to infect Apple computers running macOS. Trojan.MacOS. MacSpy .A1 typically spreads through malicious websites, compromised software downloads, phishing emails, and malicious attachments. Once Trojan.MacOS. MacSpy .A1 has infected your Mac, it can cause a variety of problems, including crashing applications, slowing ...

  • web:cyber-kill-chain.ch

    The cyber kill chain commentary by cyber-kill-chain.ch offers IT experts, forensic specialists and specialized legal advisors practice-oriented assessments and well-founded know-how.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:leaf-it.com

    MacSpy is a sophisticated new malware targeting Apple devices, capable of logging keystrokes, recording audio, taking screenshots, and even encrypting data. Learn how this threat works and why staying vigilant is essential to protecting your system.

  • web:macos.checkpoint.com

    MacSpy is Malware as a Service (MaaS). The malware authors claim that it is undetected by anti-viruses and it is offered with basic version for free, and in addition in a paid version more advanced features available such as:- File encryption (similar to Ransomware)- Access to emails- Official code signing for the malicious file- Webcam ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the MacSpy malware family including references, samples and yara signatures.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.intego.com

    In June, two research teams independently discovered a new Mac malware family , dubbed JokerSpy. One of the malware's early stages includes a cross-platform component, hinting that variants of JokerSpy may also exist for Windows and Linux as well. Let's explore what you need to know about this new Mac threat and how to stay protected.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.