Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Next task is to install the Input Manager (method _dropOsaxBundle , address 0xd871 ). It will be located at /Users/USERNAME/Library/ScriptingAdditions/appleHID ... I’m pretty sure it’s the spying component being injected into applications.
The last interesting bit is the method name called _communicateWithAgents . It’s big and still not reversed but it seems to involve shared memory... agents are the infected applications with the spying module, which dump information to the main backdoor module.
Execution will continue with a method called _resizeSharedMemoryWindow . Here some kernel shared memory settings will be changed. They are kern.sysv.shmmax , kern.sysv.shmall . Since this requires root privileges, it will only work if the backdoor module was installed as root.
If mdworker.flg is found then the method _createInternalFilesAndFolders will be called... It will create the rootkit bundle... WeP1xpBU.wA-.kext , fix the permissions to root:wheel... If the backdoor is running as root, it will try to connect to the rootkit or load it if connection failed.
Before, the kernel extension rootkit could be easily hidden from kextstat by manipulating this list. Now we must patch an I/O Kit OSArray class called sLoadedKexts
If mdworker.flg is found then the method _createInternalFilesAndFolders will be called... It will create the rootkit bundle... WeP1xpBU.wA-.kext , fix the permissions to root:wheel... If the backdoor is running as root, it will try to connect to the rootkit or load it if connection failed.
Before, the kernel extension rootkit could be easily hidden from kextstat by manipulating this list. Now we must patch an I/O Kit OSArray class called sLoadedKexts
Call method makeBackdoorResident , which will create the Launch Agent com.apple.mdworker.plist at ~/Library/LaunchAgents . This will be responsible for starting the backdoor module.
The difference between the two modes is that the Ah56K mode does not try to escalate privileges, while the other one tries it using a spoofed authentication dialog with System Preferences icon... the backdoor executable creates a copy of itself named System Preferences and launches it.
Classic kernel rootkits aka kernel extensions. Two simple ideas that can make them a lot more powerful and universal.
The trick here is that the backdoor executable creates a copy of itself named System Preferences and launches it.
The next step is to verify is a file called off.flg exists at the backdoor executable location... If it does exist, then the following will happen: Remove off.flg file.
The first important operation that is executed is to verify if the current OS is supported, using getSystemVersionMajor:minor:bugFix: method. Lion and Snow Leopard are valid targets, but also Leopard.
Execution will continue with a method called _resizeSharedMemoryWindow . Here some kernel shared memory settings will be changed. They are kern.sysv.shmmax , kern.sysv.shmall . Since this requires root privileges, it will only work if the backdoor module was installed as root.
One easy solution is to read the kernel image from disk and process its symbols... Virtual File System – VFS. Read mach_kernel using VFS functions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS surveillance/RAT tooling (linked here to HackingTeam) referenced for webcam/microphone access capabilities.
A Mac OS X malware/rootkit referenced as using a userland component to resolve kernel symbols and pass them to a kernel rootkit; also described later as having a powerful userland rootkit component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.