Phexia is a modular macOS-focused infostealer and remote-access malware family. It contains information-stealing and reverse-shell functionality and has been characterized as a resident bot designed to support additional modules. Phexia establishes user-level persistence through a LaunchAgent that executes an encoded AppleScript payload. It uses dead-drop resolution through Telegram profiles, Steam profiles, and blockchain smart contracts to retrieve or rotate command-and-control infrastructure, enabling operators to change backend infrastructure without rebuilding the malware. Phexia has been distributed through malicious copy-and-paste lures that cause victims to execute shell and AppleScript commands. It has also been associated with abuse of blockchain infrastructure for infostealer distribution. Phexia emerged in the macOS stealer ecosystem alongside families such as Atomic Stealer and MacSync Stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Phexia also uses LaunchAgent persistence to ensure execution after reboots.
followed by osascript execution that created a LaunchAgent plist file which was configured to run a bash command containing a base64-encoded payload
Once the fateful paste into a Terminal window took place, the traditional AppleScript stealer code we’ve observed in previous years executed to gather data and exfiltrate.
Popular tools like VPNs, often used by users with limited security resources, combined with legitimate command-and-control (C2) infrastructure enables attackers to reach a far wider victim base while frustrating defenders who cannot simply block the associated endpoints.
At the time of publication, Phexia is unique from other macOS stealers in its use of dead drop resolution with Telegram, Steam, and blockchain smart contracts to discover command and control (C2) domains for communication.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer distributed via abused legitimate blockchain infrastructure.
A modular macOS remote access tool and stealer that uses LaunchAgent persistence and dead-drop C2 resolution via Telegram, Steam, and blockchain smart contracts, with components partly modeled after MacSync Stealer.
An infostealer distributed via abused legitimate blockchain infrastructure.
Referenced as an established macOS stealer used for comparison with CrashStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.