s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-osx.fruitfly

📛 Threat Title

Malware family: FruitFly

Category: FruitFly First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.fruitfly`. Printable name: FruitFly. Aliases: Quimitchin.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.fruitfly VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.fruitfly

IOC database

Type
domain
Value
osx.fruitfly
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.fruitfly

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.fruitfly

References (1)

Remediations (10)

  • web:attack.mitre.org

    FruitFly is designed to spy on mac users [1]. ID: S0277

  • web:infocon.org

    OSX/ FRUITFLY an intriguing backdoor OSX/ FRUITFLY ('QUIMITCHIN') initially discovered by malwarebytes "New Mac backdoor using antiquated code"

  • web:macos.checkpoint.com

    The malware can take screenshots using the command "screencapture -x" and in addition the malware downloads and executes additional files such to enable it to scan for other computers on the same network and connect to them.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the FruitFly malware family including references, samples and yara signatures.

  • web:www.cnet.com

    The Mac malware , originally discovered back in January, creates a "backdoor" that allows the controller of the malware to take over an entire computer.

  • web:www.malwarebytes.com

    Almost seven years after alleged FruitFly author Phillip Durachinsky's arrest, judge Solomon Oliver has ruled he's incompetent to stand trial, by reason of being unable to assist in his own defense due to autism spectrum disorder (ASD).

  • web:www.neowin.net

    A piece of malware for macOS, initially discovered back in January, has been found with a new variant, which discreetly spies on host computers, steals sensitive files, and run background processes.

  • web:www.reactionarytimes.com

    The FruitFly malware attack can be mitigated by monitoring for unusual process behavior, correlated with other events, to identify malicious activity. Additionally, the creation of Launch Agents can be monitored, and file obfuscation can be detected.

  • web:www.securemac.com

    High Description Fruitfly is malware used in targeted attacks. Fruitfly Threat Removal MacScan can detect and remove Fruitfly Malware from your system, as well as provide protection against other security and privacy threats. A 30-day trial is available to scan your system for this threat. Download MacScan Start your free 30-day MacScan trial

  • web:www.securityweek.com

    Cybercrime Weak Passwords Abused for 'FruitFly' Mac Malware Distribution FruitFly , a piece of Mac malware that infected thousands of machines over the course of more than 13 years, was being distributed via poorly protected external services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.