iWorm is an OS X/macOS malware family and backdoor, commonly referred to as OSX/IWORM or iWorm. The provided content describes it as a 'standard' backdoor with survey, download, execute, and persistence capabilities. It spread via social engineering and infected torrents, and multiple sources in the content state that it infected more than 17,000 hosts by persuading users to grant administrator privileges. Persistence is explicitly described via a Launch Daemon plist at /Library/LaunchDaemons/com.JavaW.plist. The malware is associated with OS X systems and is cited in presentations on Mac malware as an example of how effective simple social-engineering-based installation could be. The content also notes a later demonstration in which iWorm was placed into /System/Library/LaunchDaemons through a System Integrity Protection bypass, after which it would be protected by SIP and difficult to remove even with root privileges. High-confidence indicators and artifacts directly mentioned in the content include the path /Library/LaunchDaemons/com.JavaW.plist and the malware name OSX/IWORM/iWorm.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A well-known OS X malware family referenced as an example of malware that can gain root via user authentication prompts and then be persisted in SIP-protected locations using the described SIP bypass technique.
A Mac botnet referenced as having infected more than 17,000 hosts by requesting admin privileges from users.
OS X backdoor that performs host survey, downloads and executes payloads, and persists via a launch daemon; the talk also notes it infected torrents.
Mac malware referenced as having infected more than 17,000 hosts through social engineering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.