s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.keydnap

📛 Threat Title

Malware family: Keydnap

Category: Keydnap First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.keydnap`. Printable name: Keydnap.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.keydnap VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keydnap

IOC database

Type
domain
Value
osx.keydnap
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.keydnap

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.keydnap

References (1)

Remediations (10)

  • web:attack.mitre.org

    Keydnap This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor [1].

  • web:en.wikipedia.org

    OSX. Keydnap is a MacOS X based Trojan horse that steals passwords from the iCloud Keychain [1] of the infected machine. It uses a dropper to establish a permanent backdoor while exploiting MacOS vulnerabilities and security features like Gatekeeper, iCloud Keychain and the file naming system.

  • web:github.com

    Indicators of Compromises (IOC) of our various investigations - malware -ioc/ keydnap /README.adoc at master · eset/ malware -ioc

  • web:handwiki.org

    OSX. Keydnap is a MacOS X based Trojan horse that steals passwords from the iCloud Keychain of the infected machine. It uses a dropper to establish a permanent backdoor while exploiting MacOS vulnerabilities and security features like Gatekeeper, iCloud Keychain and the file naming system.

  • web:macos.checkpoint.com

    Keydnap is a malware which opens a backdoor to infected machines and steals content of keychain which holds sensitive information such as passwords.The malware uses cunning techniques to trick the user to click on the malicious executable file - it adds an jpg file extensions but with the addition of spaces or other characters, such as ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Keydnap malware family including references, samples and yara signatures.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.picussecurity.com

    When a user double-clicks it, the Keydnap backdoor malware is executed. WinRAR CVE-2023-38831 Vulnerability: The CVE-2023-38831 vulnerability allows adversaries to spoof file extensions and hide their malware within an archive as an image or document file.

  • web:www.securityweek.com

    A new Mac OS X piece of malware was designed to steal the content of the keychain and to establish permanent backdoor access to the infected system, ESET security researchers warn. Dubbed OSX/ Keydnap , the new threat is supposedly distributed via malicious attachments in spam messages, but researchers say that downloads from untrusted websites might also be used as infection vectors. While the ...

  • web:www.trendmicro.com

    Scan your computer with your Trend Micro product to delete files detected as OSX_KEYDNAP.J. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.