Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The payload loaded by the Nimcore loader has been identified as SneakMain.macOS, written in the Nim programming language. Upon execution, it reads its configuration from /private/var/tmp/cfg ... and uses the osascript -e command to execute commands received from the C2 server.
SneakMain ... launch a Nim payload called SneakMain to receive and execute additional AppleScript commands received from an external server.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
RooTroy collects and lists all mounted volumes and running processes... SneakMain.macOS constructs a JSON object containing this information, along with additional fields such as... process list... SysPhon... Process list ps aux.
all three DownTroy strains collect comprehensive system information including OS details, domain name, host name, username, proxy settings, and VM detection alongside process lists... SysPhon... conduct system reconnaissance by executing a series of commands.
The page reports back to their backend infrastructure through a series of automatically triggered HTTP GET requests... RooTroy sends the collected information to the C2 server via a POST request to /update endpoint... additional files are retrieved with GET.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands... SneakMain... receives additional AppleScript commands and uses the osascript -e command to execute them.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nim payload that receives commands from an external server and executes additional AppleScript commands (command execution / tasking).
A macOS backdoor observed in Nim and earlier Rust variants. It reads encrypted configuration, sends host and process information to C2, and executes returned AppleScript commands. It appears in a modular chain with a Nimcore loader and installer-based persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.