DaVinci, also referred to in the provided content as OS.X/Crisis, is a leaked commercial spyware platform associated with HackingTeam’s DaVinci / Galileo RCS. The content describes it as containing both userland and kernel rootkit components for Mac OS X. It is referenced as a rare example of an OS X rootkit and specifically as a user/kernel rootkit with notable features and flaws.
Based on the cited material, DaVinci targeted Mac OS X and implemented stealth capabilities at the kernel level. The content states that OS.X/Crisis used a technique to hide from tools that enumerate loaded kernel extensions by interacting with the IOKit sLoadedKexts structure rather than the deprecated legacy kmod list. It also states that OS.X/Crisis solved the symbol for OSKext::lookupKextWithLoadTag in userland and passed it to the kernel rootkit via sysctl to help locate sLoadedKexts. These details indicate deliberate anti-forensic and evasion functionality designed to conceal the presence of its kernel component.
The content directly associates DaVinci with the commercial spyware industry and with private and governmental use via HackingTeam’s Galileo RCS. No specific infection vector, victim industry list, or concrete indicators of compromise are provided in the supplied content. High-confidence characteristics directly supported by the content are that it is commercial spyware for OS X, includes both userland and kernel rootkit functionality, and employs kernel-extension hiding techniques for stealth.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attachment is malicious. To the user it appears to be a Microsoft Word document, however it in fact is an RTF file containing an exploit which allows the execution of code that downloads surveillance malware. This document exploits a stack-based buffer overflow in the RTF format... aka “RTF Stack Buffer Overflow Vulnerability.”
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The page, found at http://freeme.eu5.org/scandale%20(2).doc prompted the user for the installation of malicious java, file, 'adobe.jar'. This file then facilitated the installation of a multi-platform (OSX and Windows) backdoor.
• Kernel rootkit. • 32 bits kernel extension: Lft2iRjk.7qa. • 64 bits kernel extension: 3ZPYmgGV.TOA.
• Sdbm hash used to “obfuscate” the symbols names. • Packed with MPRESS in two samples.
• Dynamically resolves all other required symbols. • Search for the dyld symbols that allow to retrieve loaded images.
• Injection into target applications. • How is the bundle injected into targets?
It is executed via rundll32... C:WINDOWSsystem32rundll32.exe "C:DOCUME~1ADMINI~1LOCALS~1jlc3V7weIZsROY7X.-MP",F1dd208 ... The following command is run, executing the file: "V46lMhsH.shv" C:WINDOWSSystem32rundll32.exe "C:DOCUME~1ADMINI~1LOCALS~1UbY5xEcDV46lMhsH.shv",F7ed728
• C&C traffic over HTTP. • Encrypted data over HTTP. • REST Protocol.
Our research reveals that the RCS collection infrastructure uses a proxy-chaining technique which is roughly analogous to that used by general-purpose anonymity solutions like Tor in that multiple hops are used to anonymize the destination of information.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware for Mac OS X described as a user/kernel rootkit with notable features and flaws.
Commercial surveillance/spyware trojan referenced as a private/governmental example; no additional technical behavior described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.