EggShell is a backdoor/post-exploitation tool for macOS and Linux. The provided content explicitly describes it as a known post-exploitation tool for those platforms and references deployment of an "EggShell backdoor" variant. ESET reported that in September 2025, the North Korea-aligned Konni group targeted macOS devices using social engineering to steal credentials and deploy a variant of the EggShell backdoor. High-confidence details in the content therefore associate EggShell with post-compromise activity on macOS and Linux, with observed use by Konni against macOS victims. No specific infection vector, persistence mechanism, command-and-control details, or indicators of compromise are provided beyond the social-engineering-led Konni campaign and the quoted references to EggShell backdoor execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor (variant deployed on macOS in the described campaign) used after credential theft to maintain access.
Post-exploitation backdoor/tool for macOS and Linux used to execute commands and maintain access after compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.