Crisis, also known as Morcut and identified as Hacking Team’s Remote Control System (RCS) / DaVinci on macOS, is a commercial spyware/implant family associated with Hacking Team. Publicly discussed samples were found for Windows, OS X, iOS, and Android, with a newer platform version referred to as Galileo. On macOS, Crisis consists of a dropper, main backdoor, spy modules, an injected bundle/XPC component, encrypted configuration, and optional 32-bit and 64-bit kernel extensions used as a rootkit.
Documented capabilities include microphone and webcam capture, screenshots, keylogging, mouse tracking, browser spying, interception/recording of Skype or Microsoft Messenger activity, arbitrary bundle injection into GUI applications, and encrypted HTTP-based command-and-control. The malware used AES-128-CBC for logs and configuration and negotiated a session key with the server during its initial authentication exchange. The first C2 communication was an HTTP POST to / over port 80; one analyzed sample communicated with 176.58.100.37. Additional infrastructure referenced in the content includes ar-24.com, 176.58.121.242, and 176.79.146.167.
On macOS, the dropper was described as a 32-bit x86 Mach-O binary that manually resolved APIs via dyld/libSystem, determined OS version from SystemVersion.plist, unpacked embedded payloads into $HOME/Library/Preferences/jlc3V7we.app/, then forked and executed the main backdoor module IZsROY7X.-MP. Persistence was established via a LaunchAgent named com.apple.mdworker in ~/Library/LaunchAgents. The backdoor suppressed Apple System Log messages by overriding asl_send(), used sysctl-based anti-debugging checks, created shared memory segments, installed an Input Manager at ~/Library/ScriptingAdditions/appleHID, and injected its bundle into running applications using AppleScript events.
The rootkit component communicated with userland through /dev/pfCPU and supported hiding files, processes, and its own kernel extension. Analyses cited separate 32-bit and 64-bit variants, file hiding by name rather than full path, and ioctl-based control without authentication or cryptography. Hidden names included com.apple.mdworker.plist, jlc3V7we.app, pfCPU, and appleHID. The rootkit was described as small and capable of hiding files and processes, but also as poorly designed and detectable in some scenarios.
Observed infection vectors in the content include exploits such as Flash or Word and social engineering. Antivirus labels across analyzed samples consistently referenced Crisis/Morcut, including ClamAV WIN.Trojan.Crisis, McAfee Morcut.a, Trend Micro JAVA_MORCUT.A, PCTools Malware.OSX-Crisis, Avast Win32:Crisis, and Sophos W32/Crisis-A. Sample hashes explicitly mentioned in the content include SHA256 10fa7fa952dfc933b96d92ccd254a7655840250a787a1b4d9889bf2f70153791 for a macOS dropper, SHA256 53cd1d6a1cc64d4e8275a22216492b76db186cfb38cec6e7b3cfb7a87ccb3524 for a JAR sample, and SHA256 c93074c0e60d0f9d33056fd6439205610857aa3cf54c1c20a48333b4367268ca for a Win32 executable.
The content also notes that Danabot operators were observed delivering Crisis as ransomware to already compromised systems, but that does not change the primary characterization in the supplied material of Crisis as a Hacking Team spyware/implant family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The leaked tools included a zero-day exploit for Adobe Flash (CVE-2015-5119) as well as sophisticated platforms capable of providing remote access, keylogging, general information recording and exfiltration.
The attachment is malicious. To the user it appears to be a Microsoft Word document, however it in fact is an RTF file containing an exploit which allows the execution of code that downloads surveillance malware. This document exploits a stack-based buffer overflow in the RTF format... aka “RTF Stack Buffer Overflow Vulnerability.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HackingTeam’s Remote Control System. Officially sold as DaVinci. Known as Crisis or Morcut. Samples found for Windows, OS X, iOS, Android. New version called Galileo.
40 distinct techniques documented for this family, organized by ATT&CK tactic.
The Crisis ransomware family, also known as Dharma, was first observed in 2016, distributed mainly by spam emails but also via manually hacked RDP access.
The page, found at http://freeme.eu5.org/scandale%20(2).doc prompted the user for the installation of malicious java, file, 'adobe.jar'. This file then facilitated the installation of a multi-platform (OSX and Windows) backdoor.
The Crisis ransomware family, also known as Dharma, was first observed in 2016, distributed mainly by spam emails but also via manually hacked RDP access.
• lionSendEventToPid does two things: – Forces AppleScript to load in the target. – Injects the bundle using AppleScript events.
After unpacking all the code and data, it will fork and execute the main backdoor module, IZsROY7X.-MP .
System calls are executed via the classic interrupt 80 call. | The next step is to find dyld address in process memory. This will be used to manually solve symbols using a simple hashing algorithm.
The Crisis ransomware family, also known as Dharma, was first observed in 2016, distributed mainly by spam emails but also via manually hacked RDP access.
the following registry entry created to ensure persistence: ... software\microsoft\windows\currentversion\run... A registry key is added which ensures the persistence of the backdoor after reboot
• Injection into target applications. • How is the bundle injected into targets?
the following registry entry created to ensure persistence: ... software\microsoft\windows\currentversion\run... A registry key is added which ensures the persistence of the backdoor after reboot
Call method makeBackdoorResident , which will create the Launch Agent com.apple.mdworker.plist at ~/Library/LaunchAgents . This will be responsible for starting the backdoor module.
The difference between the two modes is that the Ah56K mode does not try to escalate privileges, while the other one tries it using a spoofed authentication dialog with System Preferences icon... the backdoor executable creates a copy of itself named System Preferences and launches it.
• Kernel rootkit. • 32 bits kernel extension: Lft2iRjk.7qa. • 64 bits kernel extension: 3ZPYmgGV.TOA.
• Sdbm hash used to “obfuscate” the symbols names. • Packed with MPRESS in two samples.
• Dynamically resolves all other required symbols. • Search for the dyld symbols that allow to retrieve loaded images.
The contents are encrypted and their size should be always 104 bytes for this request... The first 32 bytes of the response are decrypted... The last 32 bytes of the server response are then decrypted with this session key and processed.
• Injection into target applications. • How is the bundle injected into targets?
The next step is to verify is a file called off.flg exists at the backdoor executable location... If it does exist, then the following will happen: Remove off.flg file.
It is executed via rundll32... C:WINDOWSsystem32rundll32.exe "C:DOCUME~1ADMINI~1LOCALS~1jlc3V7weIZsROY7X.-MP",F1dd208 ... The following command is run, executing the file: "V46lMhsH.shv" C:WINDOWSSystem32rundll32.exe "C:DOCUME~1ADMINI~1LOCALS~1UbY5xEcDV46lMhsH.shv",F7ed728
[Inf. Module]: Spread to VMWare %S – VMWare Installation...OK ... The strings describing the Virtual Machine infection are the same as those described in the Symantec report on the Moroccan malware.
The first important operation that is executed is to verify if the current OS is supported, using getSystemVersionMajor:minor:bugFix: method. Lion and Snow Leopard are valid targets, but also Leopard.
[Inf. Module]: Spread to VMWare %S – VMWare Installation...OK ... The strings describing the Virtual Machine infection are the same as those described in the Symantec report on the Moroccan malware.
The leaked tools included ... sophisticated platforms capable of providing remote access, keylogging, general information recording and exfiltration.
• C&C traffic over HTTP. • Encrypted data over HTTP. • REST Protocol.
The Crisis ransomware family, also known as Dharma, was first observed in 2016, distributed mainly by spam emails but also via manually hacked RDP access. Upon launch, the malware sets up persistence on a victim’s operating system and starts encrypting files...
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crisis is mentioned as ransomware downloaded onto systems already compromised by Danabot.
Referenced as OS.X/Crisis, apparently a Mac spyware/rootkit family whose exposure could occur via a simple ioctl call, according to the cited discussion.
The content indicates a malware family detected across JAR, Win32, and OSX-related signatures, commonly labeled as Crisis or Morcut. Based on the detections shown, it appears associated with trojan/dropper behavior and cross-platform variants.
A rootkit referenced as using a technique to retrieve kernel extension information on 64-bit kernels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.