Eleanor is a macOS backdoor reported by Bitdefender in 2016. It was distributed as a fake or trojanized application named "EasyDoc Convertor" hosted on the MacUpdate app-sharing site. The malware is described as a basic but feature-complete PHP backdoor for Mac computers.
Eleanor persists via three LaunchAgents: "com.getdropbox.dropbox.integritycheck.plist," "com.getdropbox.dropbox.timegrabber.plist," and "com.getdropbox.dropbox.usercontent.plist." It sets up a hidden Tor service using a binary named "conn," publishes the hidden service hostname to Pastebin via "check_hostname," and runs a PHP-based backdoor using a binary named "dbd," described as a copy of Apple’s PHP binary. The backdoor is based on the b374k shell version 3.2.3 from GitHub. The malware also includes utilities such as netcat and "wacaw," enabling capabilities including remote access and camera photo/video capture.
High-confidence indicators and artifacts mentioned in the content include the trojanized app name "EasyDoc Convertor," the three LaunchAgent plist names above, and the binaries "conn," "check_hostname," and "dbd." Apple updated XProtect with a signature to block Eleanor, labeled "OSX.Eleanor.A".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized app that installs multiple LaunchAgents, sets up a hidden Tor service, publishes the onion hostname (encrypted) to Pastebin, and provides remote control via an embedded PHP webshell (b374k), with bundled tools enabling audio/video capture.
Trojanized app that installs multiple LaunchAgents, sets up a hidden Tor service, publishes the onion hostname (encrypted) to Pastebin, and provides remote control via an embedded PHP webshell (b374k), with bundled tools enabling audio/video capture.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.