MacSpy is a macOS remote access spyware/RAT marketed as a malware-as-a-service offering. It targets Apple systems and combines surveillance, collection, persistence, and anti-analysis features. Documented capabilities include keystroke logging, clipboard theft, screenshot capture across multiple monitors, microphone recording, host profiling, and exfiltration of collected data to operator infrastructure.
MacSpy establishes persistence on macOS through a LaunchAgent and hides its installed components in a concealed directory under the user profile. It has been observed deleting original or temporary files after installation and after data staging or transmission, indicating both cleanup and defense-evasion behavior. The malware also incorporates anti-debugging and anti-virtualization or sandbox checks intended to hinder analysis and automated detonation.
For command and control, MacSpy uses Tor-based communications and routes outbound traffic through a local SOCKS proxy to reach hidden-service infrastructure. Collected information is staged locally and then transmitted via HTTP POST requests through the Tor channel. Public reporting has described it as being advertised as highly capable Mac spyware, with operators providing access through a managed portal for reviewing stolen victim data.
MacSpy is associated with macOS-focused surveillance and credential-collection activity rather than destructive operations. Its feature set and persistence model place it among espionage-oriented Mac malware families designed for long-term user monitoring and covert data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“copies itself… to ‘~/Library/.DS_Stores/’… deletes the original files in an attempt to stay hidden… launch entry… com.apple.webkit.plist”
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
“contains checks against the execution environment… checks that the number of physical CPUs… logical cores… at least 4 GB of memory… compares the machine model to ‘Mac’ using the ‘sysctl’ command.”
“the malware sends the data it had collected earlier, such as system information… Contents… SystemInfo fullUsername… hostname… os Version… memory… processorCount… identifier… uuid… disk layout”
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
AsyncRAT can proxy C2 through a Tor client. Attor has used Tor for C2 communication. Cyclops Blink has used Tor nodes for C2 traffic. GreyEnergy has used Tor relays for Command and Control servers. Siloscape uses Tor to communicate with C2. WannaCry uses Tor for command and control traffic.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware referenced as using LoginHook-based persistence on macOS.
Spyware malware that deletes temporary files it creates.
macOS spyware capable of multi-monitor desktop screenshot capture.
Malware that captures keystrokes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.