CallMe is a malware family associated with macOS and commonly referred to as the CallMe OSX Trojan. It has been described as providing reverse-shell functionality, enabling an operator to execute commands on a compromised host and maintain remote interactive control. Its command-and-control communications use AES encryption, indicating an effort to protect tasking and responses in transit. CallMe also supports exfiltration of data to its command-and-control infrastructure over the same protocol used for command-and-control communications, blending theft activity into existing traffic. The available reporting supports its use as a remote-access style implant on Apple systems, but does not provide high-confidence detail on broader delivery methods, persistence mechanisms, or specific targeting beyond macOS hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS trojan that creates a reverse shell for remote access.
Malware that exfiltrates data to its C2 server using the same protocol as its command-and-control traffic.
Backdoor that uses AES to encrypt C2 traffic.
Backdoor that exfiltrates data to its C2 server using the same protocol as its C2 traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.