XAgentOSX is a macOS variant of the XAgent espionage malware family associated with the Sofacy/APT28 intrusion set. It is a surveillance-oriented backdoor used for post-compromise collection and host reconnaissance on Apple systems. Documented functionality includes enumerating running processes, collecting operating system version and current user information, attempting to recover saved Firefox passwords, capturing screenshots through native macOS graphics APIs, logging keystrokes while tracking active application windows, executing files via native task-launch mechanisms, and deleting files from disk. Its feature set is consistent with targeted intelligence collection against compromised macOS hosts rather than broad disruptive activity. The malware’s use of native macOS frameworks for screen capture, execution, and file operations reflects platform-specific development for Apple environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS backdoor that returns OS version and current user information.
Returns the OS X version and current user.
macOS backdoor that executes specified files using NSTask launch functionality.
macOS backdoor containing functionality to locate Firefox passwords.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.