Koi Stealer
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
4 techniques
Execution
"osascript<<EOD display dialog..."; "uses AppleScript to mute the system’s volume"; "uses AppleScript again... to collect specific files"
Stealth
1 technique
Stealth
Credential Access
4 techniques
Credential Access
Discovery
3 techniques
Discovery
Collection
3 techniques
Collection
"copies multiple files of interest... Browser files... OpenVPN... Steam... Discord... Telegram... Notes... Cryptocurrency wallets"
Command and Control
2 techniques
Command and Control
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a DPRK-attributed macOS stealer whose crypto-wallet targeting list closely matches PHANTOMPULSE reconnaissance.
Infostealer with a newly documented macOS variant; performs host recon and credential capture (including prompting for admin password), steals browser/app/SSH/Keychain/Telegram/Discord/Steam/VPN/FileZilla data and extensive cryptocurrency wallet data, and exfiltrates in two stages to a C2; uses AppleScript for stealth (muting audio, targeted file collection) and runtime string decryption (XOR).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.