WindTail is a persistent macOS cyber-espionage backdoor associated with the WindShift APT group. The provided content describes it as targeting Middle Eastern governments and notes that it abused custom URL schemes to trigger malware execution on victim systems. It is characterized as a backdoor used in espionage operations rather than financially motivated activity. The content also explicitly refers to it as a persistent backdoor and mentions a repurposed version of OSX.WindTail being installed through a reverse shell in one example. High-confidence details in the source are limited to its macOS focus, persistence, use by WindShift, targeting of Middle Eastern government entities, and abuse of custom URL schemes for execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX.WindTail is a macOS backdoor that provides persistent remote access to infected systems. In this context, it is installed via a reverse shell established by exploiting a chain of vulnerabilities in Office macro handling and macOS sandboxing.
Persistent backdoor used in cyber-espionage campaigns, providing remote access and file exfiltration, targeting Middle Eastern governments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.