TF-MAL-osx.keydnap
📛 Threat Title
Malware family: Keydnap
Description
ThreatFox malware family `osx.keydnap`. Printable name: Keydnap.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.keydnap
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keydnap
IOC database
- Type
- domain
- Value
osx.keydnap- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.keydnap
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keydnap
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Keydnap This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor [1].
-
web:en.wikipedia.org
OSX. Keydnap is a MacOS X based Trojan horse that steals passwords from the iCloud Keychain [1] of the infected machine. It uses a dropper to establish a permanent backdoor while exploiting MacOS vulnerabilities and security features like Gatekeeper, iCloud Keychain and the file naming system.
-
web:github.com
Indicators of Compromises (IOC) of our various investigations - malware -ioc/ keydnap /README.adoc at master · eset/ malware -ioc
-
web:handwiki.org
OSX. Keydnap is a MacOS X based Trojan horse that steals passwords from the iCloud Keychain of the infected machine. It uses a dropper to establish a permanent backdoor while exploiting MacOS vulnerabilities and security features like Gatekeeper, iCloud Keychain and the file naming system.
-
web:macos.checkpoint.com
Keydnap is a malware which opens a backdoor to infected machines and steals content of keychain which holds sensitive information such as passwords.The malware uses cunning techniques to trick the user to click on the malicious executable file - it adds an jpg file extensions but with the addition of spaces or other characters, such as ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Keydnap malware family including references, samples and yara signatures.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.picussecurity.com
When a user double-clicks it, the Keydnap backdoor malware is executed. WinRAR CVE-2023-38831 Vulnerability: The CVE-2023-38831 vulnerability allows adversaries to spoof file extensions and hide their malware within an archive as an image or document file.
-
web:www.securityweek.com
A new Mac OS X piece of malware was designed to steal the content of the keychain and to establish permanent backdoor access to the infected system, ESET security researchers warn. Dubbed OSX/ Keydnap , the new threat is supposedly distributed via malicious attachments in spam messages, but researchers say that downloads from untrusted websites might also be used as infection vectors. While the ...
-
web:www.trendmicro.com
Scan your computer with your Trend Micro product to delete files detected as OSX_KEYDNAP.J. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.