gapi is a malicious binary used in an active social-engineering and phishing campaign targeting open-source developers in Linux Foundation communities, particularly the TODO Group/CNCF-related Slack workspaces. In the reported attack chain, an attacker impersonated a known Linux Foundation community leader on Slack and sent victims to a Google Sites phishing page at https://sites[.]google[.]com/view/workspace-business/join that mimicked a Google Workspace login flow. After harvesting credentials, the phishing flow prompted installation of a fake or malicious root certificate masquerading as a Google certificate. On macOS, an additional script downloaded and executed the gapi binary from remote IP address 2.26.97.61; OpenSSF warned that executing gapi may result in full system compromise. The malicious certificate could also enable interception of encrypted traffic and credential theft. On Windows, the campaign prompted installation of the malicious certificate through a browser trust dialog, but the provided content only directly associates gapi execution with macOS. The activity was disclosed by OpenSSF, and no confirmed attribution to a specific threat actor was reported in the provided content. High-confidence indicators directly mentioned include the binary name gapi, remote IP 2.26.97.61, phishing URL https://sites[.]google[.]com/view/workspace-business/join, fake email cra@nmail.biz, and access key CDRX-NM71E8T.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
On macOS, once the malicious root certificate was installed, a script automatically downloaded and executed a binary named gapi from a remote IP address ( 2.26.97.61 ).
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious binary delivered in a social-engineering campaign targeting open source developers. It is downloaded and executed on macOS after installation of a fake root certificate, enabling credential theft, interception of encrypted traffic, and potentially full system compromise.
A malicious binary delivered on macOS after the victim installs a malicious certificate; it is downloaded from a remote IP address and may lead to full system compromise.
A macOS-delivered malicious binary used in a social engineering campaign targeting open source developers via Slack. It is delivered after phishing and malicious certificate installation and may result in full system compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.