Proton is a macOS remote-access trojan (RAT), also tracked as OSX.Proton and Proton.B, written in Objective-C. It has been distributed through trojanized macOS software, including a compromised HandBrake application, and uses deceptive native password prompts purportedly needed to install codecs or software components. Captured passwords can be used to test and obtain elevated execution through sudo; Proton has also modified sudo configuration to weaken reauthentication controls. The malware establishes persistence using a macOS LaunchAgent and copies itself to a user-library location.
Proton collects browser profiles, saved credentials, cookies, and form data from major macOS browsers, as well as macOS keychain data, GnuPG material, and 1Password vault data. It can archive collected material before exfiltration. Reported RAT functions also include keylogging, screenshot capture, webcam access, file upload and download, and SSH and VNC connectivity. Proton uses encrypted embedded resources and configuration material, checks external connectivity and time information, terminates selected analysis tools, and deletes logs to obstruct investigation. It has been marketed in criminal forums as a macOS surveillance and control tool. A separately referenced Proton ransomware family should not be conflated with the macOS RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Proton’s authors included a few tricks meant to deceive researchers ... encrypting some of the strings and scripts and storing them in a separate file that will be decrypted upon execution.
Users of Proton still have to disguise the malware with a custom name and icon, and to somehow trick targets into downloading and installing it. The creator of Proton attempted to market it as a supposedly legitimate security tool, complete with a website advertising it as an ideal solution to prevent corporate espionage, to help administrators manage systems, and for parents to monitor their children's Internet usage.
Sixgill advises the malware's creator managed to get the code signed by Apple, suggesting it has managed to pass through Apple's rigorous filtration process for third-party software developers. It is believed the developer has either falsified their registration to the Apple Developer ID Program or used stolen credentials, in order to get through the signing process.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network. Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
With root-access privileges, the list of potential actions includes keylogging, uploading and downloading files, screenshots, webcam access, and SSH and VNC connectivity.
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A probable Iranian-origin ransomware family first observed in March 2023. It is described as a closed operation rather than an openly recruited RaaS, with purported lineage links to several variants including Shinra, Limba, and Zola.
A probable Iranian-origin ransomware family operating as a closed group rather than an openly recruited RaaS operation. Its reported lineage includes Shinra, Limba, Zola, Cipher, and Trust.
A macOS remote access trojan written in Objective C and marketed on Russian cybercrime forums. It is described as providing surveillance and control capabilities including keylogging, file upload/download, screenshots, webcam access, SSH/VNC connectivity, custom phishing-style windows, access to iCloud, and claimed root privileges via an unpatched macOS 0-day. The malware was also said to be signed with genuine Apple code-signing signatures.
Ransomware family referenced as a source of leaked code/builders for derivative variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.