OS.X/Boubou is a proof-of-concept Mach-O virus infector for macOS authored by fG! and presented at HITCON 2012 in Taipei. The published code modifies the Mach-O header of target binaries and adds a new LC_LOAD_DYLIB-style library load command so a malicious dynamic library executes when the infected application starts. The project is described as a persistence and backdooring technique that avoids more obvious mechanisms such as LaunchDaemons. The codebase consists of an infector and a library: the infector attempts to infect applications found in a configured path (defined in configuration.h), first trying frameworks and then the main binary, while the library decrypts and restores bytes altered or stolen by the infector. The author states the payload could be used for information theft or backdoor access, but also emphasizes the release is a cleaned-up, intentionally imperfect proof of concept rather than production-grade malware and contains design choices that make it easily detectable. High-confidence limitations directly stated in the content are that this version supports only non-fat Mach-O targets, either 32-bit or 64-bit binaries and frameworks, and that LC_MAIN handling and reliable main-binary infection were unfinished, with main-binary infection reportedly only occurring in debug builds at that stage. Associated context links the technique to launchd/dyld execution flow and later discussions of persistence via binary infection on macOS. A directly provided artifact is osx_boubou_v0.1.zip with SHA-256 4e5429aeca58f8d6aea89034409804cc4a8a787fc56b1ce617bb28071eb8d0ce.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mac OS X proof-of-concept referenced for using a dyld-based injection approach.
Referenced in the bibliography as a Mach-O infector proof of concept for OS X; no further details are provided in the main content excerpt.
A proof-of-concept macOS backdoor installation technique discussed in relation to HITCON'12, intended to demonstrate how attackers could install backdoors while avoiding typical LaunchDaemons-based persistence.
Referenced as an example related to persistence via binary infection on OS X.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.