JOKERSPY is a cross-platform backdoor toolkit comprising Python implants and a macOS Swift component. The Python backdoors support host profiling, command and Python-code execution, filesystem navigation and manipulation, local payload execution, configuration changes, and bidirectional file transfer. One component can retrieve and execute additional payloads on macOS and Linux, while the toolkit’s host discovery collects system, user, process, network, operating-system, runtime, and architecture information. The macOS component checks Transparency, Consent, and Control permissions, including Full Disk Access, Screen Recording, and Accessibility, and has been associated with attempted manipulation of TCC protections. JOKERSPY activity was observed in the REF9134 intrusion against a Japan-based cryptocurrency service provider, where it was used to deploy the Swiftbelt macOS enumeration utility. The toolkit employs configuration storage, beaconing, custom command-and-control communication, and limited string obfuscation. It is supported on macOS, Linux, and Windows, although the observed intrusion activity centered on macOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor receives a cmdType 501 command ... as well as the results of the following commands: ifconfig -a ... on a Unix system; ipconfig /all ... on a Windows machine.
The backdoor receives a cmdType 501 command, it extracts details such as Current Time, Username, Hostname, OS Version.
These details are also written to a file received as an argument – in our case, the file is called called b.dat ... ps -ef when executed on a Unix system; ipconfig /all and tasklist /svc when executed on a Windows machine.
xcc checks for permissions managed by Apple's TCC (Transparency, Consent and Control), such as Full Disk Access, Screen Recording and Accessibility.
When the backdoor receives a cmdType 501 command, it extracts details such as Current Time, Username, Hostname, OS Version, as well as the results of the following commands: ifconfig -a and ps -ef when executed on a Unix system; ipconfig /all and tasklist /svc when executed on a Windows machine.
The malware then enters a while True loop where it attempts to communicate with a remote server using a custom packet format. These packets start with either GITHUB_RES or GITHUB_REQ + the UID generated in the previous step.
For MacOS devices, the function writes a file to /Users/Shared/AppleAccount.tgz. The content that is written to the archive is also encoded as base64 when received from server. It unpacks the archive to the /Users/Shared folder, then opens the /Users/Shared/TempUser/AppleAccountAssistant.app application.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS-focused backdoor/toolset used in the REF9134 intrusion. The Python-based sh.py backdoor loads configuration from ~/Public/Safari/sar.dat, beacons to C2, collects host information, and supports commands for shell execution, file transfer, configuration updates, and execution of additional payloads. The associated xcc component is a self-signed Swift binary used to evaluate system permissions and assist in TCC bypass activity.
A macOS intrusion toolset comprising the Python-based sh.py backdoor and the Swift-based xcc binary. sh.py beacons to configured C2 URLs, inventories host details, executes shell or Python commands, transfers files, and can update its configuration. xcc evaluates TCC-related permissions and was used after an attempt to replace the macOS TCC database, apparently to evade user-facing permission prompts.
A multi-component cross-platform malware toolkit targeting macOS primarily, with Python backdoors for macOS, Windows, and Linux and a Swift macOS component that checks TCC permissions likely in preparation for spyware activity such as screen capture. Components support host reconnaissance, command execution, file upload/download, configuration management, and execution of additional payloads.
Mentioned only as prior Elastic research related to a code-signing technique associated with DPRK activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.