EvilOSX is a macOS post-exploitation malware/tool. The provided content identifies it as one of several popular macOS post-exploitation tools, alongside MacPEAS, MacShellSwift, and chainbreaker, and states that such tools can be used by operators to identify possible exploits and privilege-escalation paths by assessing stored credentials, user permissions, kernel version information, and distribution version information. The content also associates EvilOSX with APT31 (also known as BRONZE VINEWOOD, Zirconium, and Judgment Panda), describing it as one of multiple malware families used by that group. In the cited reporting, APT31 is accused of deploying EvilOSX via fake Adobe Flash update pages. High-confidence context from the content therefore links EvilOSX to macOS post-exploitation activity and to APT31 operations using fake Flash update lures. No malware-specific indicators of compromise beyond the name and delivery theme are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling-wise, APT31 initially used... EvilOSX... The defendants are also accused of creating fake Adobe Flash update pages to deploy the EvilOSX malware.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS post-exploitation tool and remote access framework referenced among popular tools used after initial compromise.
macOS malware used by APT31, including delivery via fake Adobe Flash update pages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.