Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The CosmicDoor chain begins with an injector malware that we have named “GillyInjector” written in C++, which was also described by Huntress and SentinelOne.
CosmicDoor, which uses a C++ binary loader called GillyInjector (aka InjectWithDyld) to run a benign Mach-O app and inject a malicious payload into it at runtime.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
When executed with the --d flag, GillyInjector activates its destructive capabilities. It begins by enumerating all files in the current directory and securely deleting each one... The dropper... deletes them along with the plist file in order to erase any trace of their existence.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ loader/injector used to execute a benign Mach-O and inject a malicious payload at runtime. When invoked with a specific flag (--d), it is described as having destructive wiping behavior for files in the current directory.
A macOS process injector written in C++ that decrypts a benign base application and an embedded malicious payload, then injects the payload into the benign process at runtime. It supports destructive wiping mode and is used to deliver CosmicDoor, RooTroy, and RealTimeTroy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.