OSX.NetWire.A is a persistent macOS backdoor/RAT identified in targeted attacks against employees of cryptocurrency exchanges. In the reported 2019 campaign, it was delivered via a Firefox zero-day exploit (CVE-2019-11707) reached through a spear-phishing email and malicious link; the payload was a macOS binary named Finder.app. The malware installs itself in ~/.defaults/Finder.app and establishes persistence through both a launch agent (com.mac.host.plist) and a login item. It communicates with a command-and-control server at 89.34.111.113:443 and stores encrypted configuration data, including C2 settings, in .settings.conf within its application bundle; strings and configuration are decrypted at runtime to hinder analysis. Reported capabilities include host and environment reconnaissance; collecting user, host, CPU, OS version, and environment variable information; file operations such as create, rename, and delete; process listing and termination; arbitrary shell command execution via /bin/sh or /bin/bash; screenshot capture; synthetic keyboard and mouse event generation; and self-uninstallation by removing its launch agent, binary, and login item. The sample analyzed was a 32-bit macOS application compatible with versions as old as OS X 10.5, and analysis noted use of standard C/Linux-style APIs rather than macOS-specific APIs. The malware is described as a variant related to an older 2012 NetWire/Wirenet sample but with different objectives. In this campaign it bypassed macOS Gatekeeper and XProtect because exploit-based delivery did not set the quarantine attribute; at the time of analysis, the C2 server was offline. Known sample hashes: MD5 DE3A8B1E149312DAC5B8584A33C3F3C6, SHA1 23017A55B3D25A2597B7148214FD8FB2372591A5, SHA256 07A4E04EE8B4C8DC0F7507F56DC24DB00537D4637AFEE43DBB9357D4D54F6FF4.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX.NetWire.A is a persistent macOS backdoor and password-stealing trojan. It is capable of keylogging and stealing credentials from browsers and other applications. The malware achieves persistence via both a launch agent and a login item, ensuring it runs at user login. It is related to earlier OSX.Netwire samples but has evolved in functionality and objectives.
OSX.NetWire.A is a macOS backdoor (RAT) that was deployed via a Firefox 0day exploit targeting cryptocurrency exchange employees. It installs itself persistently, communicates with a remote C2 server, and provides a wide range of remote access and control capabilities, including file manipulation, process control, system survey, arbitrary command execution, screenshot capture, and synthetic input event generation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.