Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Tsunami
Technical ID: osx.tsunami
APT GROUP
Malware family identifying osx.tsunami. Origin and technical characteristics tracked via Malpedia.
systemd
Technical ID: osx.systemd
APT GROUP
General purpose backdoor
Also known as: Demsty • ReverseWindow
SysJoker
Technical ID: osx.sysjoker
APT GROUP
Malware family identifying osx.sysjoker. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.sugarloader. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.spectral_blur. Origin and technical characteristics tracked via Malpedia.
APT GROUP
SimpleTea is a RAT for macOS that is based on the same object-oriented project as SimpleTea for Linux (SimplexTea).
It also shares similarities with POOLRAT (also known as SIMPLESEA), like the supported commands or a single-byte XOR encryption of its configuration. However, the indices of commands are different.
SimpleTea for macOS was uploaded to VirusTotal from Hong Kong and China in September 2023.
Silver Sparrow
Technical ID: osx.silver_sparrow
APT GROUP
According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been distributed without payload so far.
Shlayer
Technical ID: osx.shlayer
APT GROUP
According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote fake search engines. It is typically disguised as a Adobe Flash Player installer and various software cracking tools.
In most cases, users encounter this virus when visiting dubious Torrent websites that are full of intrusive advertisements and deceptive downloads.
APT GROUP
Malware family identifying osx.rustbucket. Origin and technical characteristics tracked via Malpedia.
Dok
Technical ID: osx.retefe
APT GROUPfinancialhigh
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.
Also known as: Retefe
Pwnet
Technical ID: osx.pwnet
APT GROUP
Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
Pureland
Technical ID: osx.pureland
APT GROUP
According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
Proton RAT
Technical ID: osx.proton_rat
APT GROUPespionageadvanced
Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems. It is known for providing attackers with complete remote control over the infected system, allowing the execution of commands, keystroke capturing, access to the camera and microphone, and the ability to steal credentials stored in browsers and other password managers. This malware typically spreads through malicious or modified applications, which, when downloaded and installed by unsuspecting users, trigger its payload. Proton RAT is notorious for its sophistication and evasion capabilities, including techniques to bypass detection by installed security solutions.
Also known as: Calisto
Poseidon Stealer
Technical ID: osx.poseidonstealer
APT GROUP
macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.
Also known as: Rodrigo Stealer
Poseidon
Technical ID: osx.poseidon
APT GROUP
Part of Mythic C2, written in Golang.
APT GROUP
Malware family identifying osx.poolrat. Origin and technical characteristics tracked via Malpedia.
Also known as: SIMPLESEA • SIMPLETEA
Pirrit
Technical ID: osx.pirrit
APT GROUP
Malware family identifying osx.pirrit. Origin and technical characteristics tracked via Malpedia.
PintSized
Technical ID: osx.pintsized
APT GROUP
Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments. “PuffySSH_5.8p1” string.
Pearl Stealer
Technical ID: osx.pearl_stealer
APT GROUP
Malware family identifying osx.pearl_stealer. Origin and technical characteristics tracked via Malpedia.
Patcher
Technical ID: osx.patcher
APT GROUPfinancialhigh
This crypto-ransomware for macOS was caught spreading via BitTorrent distribution sites in February 2017, masquerading as 'Patcher', an application used for pirating popular software like Adobe Premiere Pro or Microsoft Office for Mac.
The downloaded torrent contained an application bundle in the form of a single zip file. After launching the fake application, the main window of the fake cracking tool was displayed.
The file encryption process was launched after the misguided victim clicked 'Start'. Once executed, the ransomware generated a random 25-character string and set it as the key for RC4 encryption of all of the user's files. It then demanded ransom in Bitcoin, as instructed in the 'README!' .txt file copied all over the user's directories.
Despite the instructions being quite thorough, Patcher lacked the functionality to communicate with any C&C server, and therefore made it impossible for its operators to decrypt affected files. The randomly generated encryption key was also too long to be guessed via a brute-force attack, leaving the encrypted data unrecoverable in a reasonable amount of time.
Also known as: FileCoder • Findzip
OSAMiner
Technical ID: osx.osaminer
APT GROUP
Malware family identifying osx.osaminer. Origin and technical characteristics tracked via Malpedia.
oRAT
Technical ID: osx.orat
APT GROUP
SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
Olyx
Technical ID: osx.olyx
APT GROUP
Malware family identifying osx.olyx. Origin and technical characteristics tracked via Malpedia.
Odyssey Stealer
Technical ID: osx.odyssey_stealer
APT GROUP
Malware family identifying osx.odyssey_stealer. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.
The OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).
NetWire
Technical ID: osx.netwire
APT GROUP
Malware family identifying osx.netwire. Origin and technical characteristics tracked via Malpedia.
Mughthesec
Technical ID: osx.mughthesec
APT GROUP
Malware family identifying osx.mughthesec. Origin and technical characteristics tracked via Malpedia.
Mokes
Technical ID: osx.mokes
APT GROUP
Malware family identifying osx.mokes. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.manuscrypt. Origin and technical characteristics tracked via Malpedia.
MaMi
Technical ID: osx.mami
APT GROUP
Malware family identifying osx.mami. Origin and technical characteristics tracked via Malpedia.
MacVX
Technical ID: osx.macvx
APT GROUP
Malware family identifying osx.macvx. Origin and technical characteristics tracked via Malpedia.
MacSpy
Technical ID: osx.macspy
APT GROUP
Malware family identifying osx.macspy. Origin and technical characteristics tracked via Malpedia.
MacRansom
Technical ID: osx.macransom
APT GROUP
Malware family identifying osx.macransom. Origin and technical characteristics tracked via Malpedia.
MacInstaller
Technical ID: osx.macinstaller
APT GROUP
Malware family identifying osx.macinstaller. Origin and technical characteristics tracked via Malpedia.
MacDownloader
Technical ID: osx.macdownloader
APT GROUP
Malware family identifying osx.macdownloader. Origin and technical characteristics tracked via Malpedia.
LockBit
Technical ID: osx.lockbit
APT GROUP
Malware family identifying osx.lockbit. Origin and technical characteristics tracked via Malpedia.
LIGHTSPY
Technical ID: osx.lightspy
APT GROUP
According to Volexity, LIGHTSPY is a multi-platform malware family with documented variants for Android, iOS, and macOS.
Leverage
Technical ID: osx.leverage
APT GROUP
Malware family identifying osx.leverage. Origin and technical characteristics tracked via Malpedia.
Laoshu
Technical ID: osx.laoshu
APT GROUP
Malware family identifying osx.laoshu. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.lambert. Origin and technical characteristics tracked via Malpedia.
Also known as: GreenLambert