Keydnap, also known as OSX/Keydnap, is a macOS malware family centered on a downloader and a persistent backdoor built to steal credentials from the macOS Keychain and provide remote access. It emerged in 2016 and is notable for combining social-engineering lures, supply-chain distribution, credential prompting, and Tor-related command-and-control tradecraft.
Keydnap has been observed in at least two delivery patterns. Early activity used ZIP archives containing Mach-O executables disguised as benign files such as images or text documents, with deceptive naming and icon tricks intended to cause execution through Terminal while presenting a decoy document to the victim. The downloader then retrieved and launched the backdoor while replacing itself with lure content. Keydnap was also distributed in a supply-chain compromise involving a trojanized version of the Transmission BitTorrent client hosted on the project’s official website in late August 2016. In that incident, the malicious application was signed with a valid Apple Developer ID, allowing it to bypass Gatekeeper protections.
The backdoor component is designed to persist on infected Macs through LaunchAgents and to maintain a long-term foothold. It stores its payload under an application-support style directory, records runtime metadata, and can install persistence either in user space or system-wide depending on privileges. When running with elevated rights, it can configure itself to execute with root privileges later. It also disguises its process name to resemble legitimate system activity.
A core function of Keydnap is theft of secrets from the macOS Keychain. Its keychain-dumping logic has been reported to reuse code from the public Keychaindump proof of concept, enabling extraction of passwords and keys from the victim system. Keydnap can also present a fake macOS administrator credential prompt to harvest the user’s password, which can then be used to gain elevated privileges and facilitate broader credential theft.
Keydnap communicates with command-and-control infrastructure over HTTPS and has used Tor-related infrastructure for anonymity. Earlier variants relied on Tor2Web proxying to reach onion-hosted services, while later variants added a standalone Tor client and local proxy configuration to access onion services directly. Reported tasking includes beaconing, keychain exfiltration, self-update, payload download and execution, Python script execution, arbitrary command execution, privilege escalation support, and uninstall functionality. Some variants also supported changing and persisting the command-and-control server address.
The malware has been associated with modified UPX packing and custom obfuscation changes intended to complicate analysis. Observed versions include multiple 1.3.x releases and a later 1.5 variant tied to the Transmission compromise. Public reporting has not conclusively established the original operators or full victimology, though the lures and decoys suggest targeting of macOS users through socially engineered files and opportunistic software-distribution compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
OSX/Keydnap was distributed on a trusted website... via a recompiled version of the otherwise legitimate open source BitTorrent client application Transmission and distributed on their official website.
Command ID Description ... 4 Decode and execute a base64-encoded Python script ... 6 Download and execute a Python script from a URL ... 7 Execute a command and report the output back to the C&C server
The archive file contains a Mach-O executable file with an extension that looks benign, such as .txt or .jpg. However, the file extension actually contains a space character at the end, which means double-clicking the file in Finder will launch it in Terminal and not Preview or TextEdit.
It reads securityd’s memory and searches for the decryption key for the user’s keychain.
maintain a permanent backdoor... $HOME/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist ... $HOME/Library/LaunchAgents/com.geticloud.icloud.photo.plist
It is still packed with the modified UPX described in our first article about Keydnap.
The ZIP also contains the Resource fork that contains the icon of the executable file. It mimics the icon Finder usually applies to JPEG or text files to increase the likelihood the recipient will double-click the file.
To camouflage the location of the malicious file, Keydnap replaces argv[0] with /usr/libexec/icloudsyncd –launchd netlogon.bundle.
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
The OSX/Keydnap backdoor is equipped with a mechanism to gather and exfiltrate passwords and keys stored in OS X’s keychain.
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
The RC4 key used to encrypt HTTP POST data and decrypt the response changed... The hardcoded C&C URL is now hxxp://t4f2cocitdpqa7tv.onion/api/osx
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The FRP client can be configured to connect to the server through a proxy. The server component of SystemBC has used SOCKS5 for C2 communication. Keydnap uses a copy of tor2web proxy for HTTPS communications.
A significant change in the new version is the presence of a standalone Tor client. This enables Keydnap to reach its onion-routed C&C server without the need of a Tor2Web relay
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Software changes: ... Keydnap
Mentioned only as an antivirus detection label applied to the sample; the author explicitly questions the linkage and does not identify commonalities with the analyzed malware.
Backdoor that uses a tor2web proxy copy for HTTPS communications.
macOS malware that uses a Launch Agent for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.