OSX/MaMi is a macOS malware family discovered in 2018 that hijacks network configuration to redirect victim traffic through attacker-controlled infrastructure. Its defining behavior is modification of DNS settings on infected systems and installation of a rogue trusted root certificate into the system keychain, enabling interception and manipulation of network traffic and creating conditions for adversary-in-the-middle activity. This combination can facilitate credential theft, traffic tampering, content injection, and broader post-compromise abuse of web sessions and encrypted communications.
The malware is an unsigned Mach-O executable for macOS. It alters system network settings, including DNS configuration, and has been associated with use of native macOS tooling for network configuration changes. Although it was not observed to rely on robust launch-item persistence by default and may delete its own executable after execution, the configuration changes it leaves behind can remain in effect until manually remediated. Reported functionality also includes command execution, file transfer, screenshot capture, simulated mouse events, and AppleScript-related control, indicating broader remote-access and post-exploitation potential beyond DNS hijacking alone.
OSX/MaMi has been assessed as closely related to the Windows malware DNSUnlocker, with similarities in operational design and certificate-based traffic interception. Its initial infection vector was not conclusively established, though social-engineering-based delivery has been considered plausible. The malware targets macOS systems and is notable for abusing trusted certificate installation and DNS manipulation rather than sophisticated exploitation, making it effective through persistent system misconfiguration and traffic interception.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS DNS hijacker referenced in the resources section.
OSX/MaMi is a macOS malware that hijacks DNS settings and installs a malicious root certificate, enabling attackers to perform man-in-the-middle attacks, steal credentials, or inject ads. It can also take screenshots, simulate mouse events, download/upload files, and execute commands. The malware modifies system configuration files to change DNS servers and installs a root certificate to facilitate traffic interception.
OSX/MaMi is a DNS hijacker for macOS, modifying DNS settings and installing a malicious certificate to intercept network traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.