Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Chainbreaker can be used to extract the following types of information from an OSX keychain... Internet Passwords Generic Passwords Private Keys Public Keys X509 Certificates Secure Notes Appleshare Passwords... Given the keychain unlock password, a master key obtained using volafox or volatility, or an unlock file such as SystemKey, Chainbreaker will also provide plaintext passwords.
Dump items stored in an OSX Keychain... --dump-keychain-password-hash ... --dump-generic-passwords ... --dump-internet-passwords ... --unlock-file UNLOCK_FILE
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS post-exploitation tool associated with extracting or analyzing stored credentials, referenced as part of a toolkit for identifying escalation paths.
An open-source macOS keychain extraction tool used within the malicious installer/script chain to retrieve passwords, keys, and certificates from the victim’s keychain database.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.