OSX/Proton is a macOS backdoor and information-stealing remote access trojan known for being distributed through software supply-chain compromises. It was notably delivered via trojanized versions of legitimate macOS applications including HandBrake, Elmedia Player, and Folx after attackers compromised official distribution infrastructure or repackaged trusted software inside malicious wrappers.
On infected systems, OSX/Proton uses social engineering to obtain elevated privileges by presenting a fake authorization prompt. After gaining access, it establishes persistence through launch agent mechanisms and installs a resident component that survives reboots or user logins. The malware supports remote command execution and file-management operations, enabling operators to download and upload files, create, copy, archive, and delete data, search the filesystem, and maintain command-and-control communications, including tunneling functionality.
OSX/Proton is also a broad credential and data theft platform. Documented collection targets include browser histories, cookies, bookmarks, and stored login data from major macOS browsers; SSH material; macOS keychain contents; VPN configurations; GnuPG data; 1Password data; cryptocurrency wallet data; installed application inventories; and host profiling information such as system configuration and user details. Variants associated with the HandBrake compromise were identified as Proton.B, a newer variant that retained the core persistence and theft behavior while differing in some feature coverage from earlier samples.
The malware targets macOS users and has been associated especially with opportunistic compromise of users downloading popular consumer software, as well as theft of credentials, cryptocurrency-related assets, and other sensitive local secrets. Because administrator credentials and stored secrets may be exposed during infection, remediation has historically required full system rebuilds and rotation of compromised credentials and keys.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS remote access trojan/backdoor distributed via trojanized software installers in a supply-chain attack. It gains persistence, steals extensive system and user data including browser data, cryptocurrency wallets, SSH keys, keychain data, VPN and GnuPG data, can execute commands, upload/download files, self-update, and create SSH tunnels.
OSX/Proton is a macOS remote access trojan (RAT) and credential stealer. It is capable of gaining persistence, stealing user credentials via fake authentication popups, and providing remote access to the infected system. The variant discussed here (OSX/Proton.B) was distributed via a trojanized HandBrake installer and attempts to elevate privileges and install itself persistently as 'activity_agent.app'.
OSX/Proton is a backdoor/trojan for macOS, distributed via trojanized applications such as HandBrake, providing persistent remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.