EggShell is a post-exploitation backdoor used against macOS and, in some reporting, Linux systems. It is associated with espionage activity and has appeared both as a public tool and in customized variants deployed in targeted intrusions. Documented variants have been used in developer-focused compromise chains and in North Korea-linked operations targeting cryptocurrency and technology-adjacent victims.
On macOS, EggShell variants have been delivered through multiple infection vectors, including trojanized Xcode projects that abuse Xcode Run Script functionality and later-stage deployment from multi-stage malware chains. In one developer-focused campaign commonly tracked as XcodeSpy, a malicious Xcode project installed a customized EggShell payload on Apple developer systems. In later DPRK-linked activity attributed to Konni, an EggShell variant was deployed as a secondary implant in a macOS intrusion set aimed at cryptocurrency industry professionals using social-engineering lures.
Observed EggShell capabilities include shell access, file upload and download, file-system operations, persistence via LaunchAgents, keylogging, screenshot capture, clipboard monitoring, microphone recording, and camera capture. Some variants also support command-and-control rotation and custom data encoding. These features make EggShell suitable for surveillance-heavy post-compromise operations focused on credential collection, monitoring of victim activity, and theft of sensitive files or communications.
EggShell has been linked to customized Objective-C Mach-O implants on macOS and has been used as a modular surveillance backdoor rather than a mass-distributed commodity threat. Reported targeting has included Apple developers and organizations of intelligence interest, as well as cryptocurrency-related entities in campaigns blending espionage and financially motivated objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A Second Implant: The Objective-C EggShell Variant ... this compiled Objective-C Mach-O binary shares C2 infrastructure with FileRATClient, adding audio and camera capture.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses the ASObjC bridge to spawn a real NSWindow — indistinguishable from a genuine macOS dialog... Title: "Software Update" ... "Enter your password."
MITRE ATT&CK TTPs Input Capture: GUI Input Capture | XcodeSpy can prompt users for credentials with a seemingly legitimate prompt via AppleScript T1056 002.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS Objective-C implant associated with the same Konni infrastructure, providing surveillance functions including clipboard monitoring, screenshots, keylogging, microphone recording, camera capture, shell access, file operations, and C2 rotation, with anti-analysis and LaunchAgent persistence.
Backdoor (variant deployed on macOS in the described campaign) used after credential theft to maintain access.
A macOS backdoor whose customized variants in this campaign provide persistence, AV recording, screen capture, keylogging, file handling, and C2 communications. In this case it is the payload installed by XcodeSpy.
Post-exploitation backdoor/tool for macOS and Linux used to execute commands and maintain access after compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.