OSX.MaMi is macOS malware identified in the provided content as a DNS hijacker. It modifies infected users’ DNS settings and installs a malicious certificate into the System keychain, enabling remote attackers to access and potentially intercept all network traffic via man-in-the-middle activity. The content notes this was likely used for adware-related purposes. It is referenced as one of the notable macOS malware families observed in 2018, alongside threats such as CrossRAT and CreativeUpdate. No specific threat actor, infection vector, industries targeted, or indicators of compromise beyond the DNS-setting changes and malicious certificate installation are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DNS hijacker that redirects traffic to attacker-controlled servers, enabling man-in-the-middle attacks, ad injection, and search result redirection.
Referenced as earlier Mac malware seen that year; no additional behavioral details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.