OSX.FruitFly is a macOS backdoor and long-running espionage malware family discovered in 2017 but assessed to have operated on victim systems for years before public identification. It is notable for its unusual implementation, relying heavily on Perl-based components with helper modules including native and Java elements. The malware communicates with a command-and-control server, executes attacker-supplied commands, captures screenshots, and exfiltrates data from compromised Macs.
FruitFly is associated with covert surveillance activity against large numbers of victims, including infections identified in institutional environments. Its functionality supports persistent remote access and post-compromise monitoring rather than overt disruption. Reported behavior includes use of synthetic mouse and keyboard events on macOS to interact with the user interface and dismiss security prompts, enabling unauthorized access to protected resources and facilitating stealthy operator control.
The malware targets macOS systems and has been characterized as an all-purpose backdoor oriented toward spying and remote administration. Public reporting tied the campaign to Phillip Roman Durachinsky following a U.S. criminal investigation that identified thousands of victims. FruitFly is significant both for its longevity on macOS and for demonstrating how attackers could abuse native automation and input-simulation mechanisms to bypass user-facing security controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
elsif(!system(($m ? 'screencapture -x' : 'xwd -silent -root '. '-display :0.0 | convert xwd:-'). ' /tmp/scrn.png')) { ... A "\2".K($v) }
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a macOS spying malware example in the context of covert microphone and webcam access.
OSX.FruitFly is a Mac malware/backdoor capable of generating synthetic mouse and keyboard events to interact with the UI, allowing it to bypass security prompts and perform actions such as dumping the user's keychain.
A macOS backdoor implemented primarily as a Perl-based first stage with helper components including a Mach-O binary, a Java class, and another Perl script. It communicates with command-and-control infrastructure, executes commands, captures screenshots, and exfiltrates data from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.