Mokes is a cross-platform backdoor family targeting desktop operating systems including Linux, Windows, and macOS. It is designed for covert surveillance and remote control, with capabilities that include screenshot capture, keystroke logging, audio capture, and theft of user data. macOS reporting also attributes video or webcam capture support and document discovery focused on common office file types. The malware is implemented in C++ using the Qt framework, and early Linux and Windows variants shared closely aligned functionality and command-and-control design.
On Linux, Mokes has been observed copying itself into user-accessible application-data locations and establishing persistence through desktop autostart mechanisms. On Windows, it installs itself under user profile application-data locations and persists through Run-key autostart entries. On macOS, it has been associated with LaunchAgent-based persistence. Across platforms, Mokes communicates with hardcoded command-and-control infrastructure, sends periodic heartbeat traffic, and uses an additional encrypted channel for commands and data transfer.
Observed Windows variants include active keylogging, screenshot collection, arbitrary data staging, and code for camera capture; later samples also activated audio recording. Linux samples include code for audio capture and keylogging alongside screenshot and data collection functionality, although some analyzed builds did not enable every surveillance module at runtime. The family has been described as a standard but feature-rich desktop backdoor oriented toward espionage and user monitoring rather than destructive effects.
The initial infection vector is not firmly established across all platforms. Mokes has been observed in malicious distribution campaigns, including delivery through compromised websites masquerading malware as a security certificate update. It has also been noted in broader macOS malware reporting during 2016. Public reporting does not support a single definitive threat-actor attribution for Mokes from the supplied facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Keydnap: "creates two launch agents"; Eleanor: "installs three(!) launch agents"; Mokes: "installing itself launch agent via the storeuserd.plist"; Komplex: "persists via ~/Library/LaunchAgents/com.apple.updates.plist"
Keydnap: "creates two launch agents"; Eleanor: "installs three(!) launch agents"; Mokes: "installing itself launch agent via the storeuserd.plist"; Komplex: "persists via ~/Library/LaunchAgents/com.apple.updates.plist"
After the malware has executed its own copy in the new location, the SetWindowsHook API is utilized to establish keylogger functionality... The malware then collects gathered information from the keylogger... /tmp/kk0-DDMMyy-HHmmss-nnn.kkt
The malware then collects gathered information from the keylogger, audio captures and screenshots in /tmp/... /tmp/ss0-DDMMyy-HHmmss-nnn.sst (Screenshots, JPEG, every 30 sec.)
From this point, it performs an http request every minute... once per minute it sends a heartbeat signal via HTTP (GET /v1).
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
In June 2019, miscreants spread NetWire malware in a broad public attack, leveraging a zero-day vulnerability in Firefox. Mac malware on the rise again; several new threats found: Netwire, Mokes, LoudMiner, NewTab
A backdoor also distributed in the same fake-update campaign earlier in January.
Malware distributed in a campaign masquerading as a security certificate update; packed/loaded via NSIS and uses Microsoft Crypto API to decrypt final payload (campaign-level detail).
Backdoor with LaunchAgent persistence (e.g., storeuserd.plist) and broad collection capabilities including screenshots, audio/video capture, keystrokes, and document theft; may copy itself into multiple masqueraded locations under ~/Library.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.