OSX.Dummy is a macOS backdoor first referenced in content dated 2018-06-29. It was described as new Mac malware targeting the cryptocurrency community, specifically members of the crypto-mining community. The supporting content characterizes Dummy as a persistent interactive backdoor and states it was distributed via social engineering in Slack and Discord. High-confidence reporting in the provided material identifies it as targeting cryptocurrency users, but does not provide further technical detail on its internal functionality, command-and-control, persistence mechanism implementation, indicators of compromise, or specific attributed threat actor. No victim organizations, campaign name, or concrete IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS malware family referenced as targeting the cryptocurrency community.
Interactive backdoor that provides a reverse shell to attackers, targeting the cryptocurrency community via social engineering in chat groups.
Mac malware reported as targeting the cryptocurrency community.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.