Apfell is an open-source macOS command-and-control agent in the Mythic framework, implemented in JavaScript for Automation (JXA) and executed through the macOS automation runtime. It supports operator-directed post-exploitation activity on macOS, including host reconnaissance, screenshot capture, browser-data theft, and credential capture through fake password prompts. Apfell has been deployed through malicious software supply-chain campaigns targeting macOS development systems, where installation-time package scripts retrieve and execute JXA payloads. It has also been incorporated into Office-macro execution chains that invoke macOS scripting utilities to retrieve and run the agent. Apfell is associated with the Mythic C2 ecosystem and is distinct from Mythic's Poseidon macOS agent and Apollo Windows agent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
This script generates an Office macro which uses osascript to download and execute the Mythic JXA .js payload.
Рабочее решение — apfell-агент, который работает через osascript (AppleScript, T1059.002, Execution) и не зависит от архитектуры процессора. Callback через osascript проходит на arm64 без проблем.
This script generates an Office macro which uses osascript to download and execute the Mythic JXA .js payload.
The same is true for installing C2 Profiles: sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http | Installing Agents and C2 Profiles The Mythic repository itself does not host any Payload Types or any C2 Profiles... sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier macOS-focused project from which Mythic was developed as a successor.
Mythic C2 JXA agent used on macOS to conduct reconnaissance, collect screenshots, steal data from Google Chrome, and capture system passwords via a fake prompt.
Open-source Mythic agent for macOS (JavaScript) delivered via the malicious npm package’s preinstall chain; provides post-compromise capabilities such as host reconnaissance, screenshot capture, Chrome data theft, and credential/prompting via fake password dialogs.
macOS JXA agent used for extensive data collection and privilege-establishing actions such as creating a new admin user.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.