Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SentinelOne identified an additional victim infected with the macOS backdoors, FLATROOF (aka macOS.Gaslight) and ROOFDECK, which were first observed in the LayerZero attack.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
FLATROOF was deployed as SystemUpdate; ROOFDECK was deployed as iSync and later loginwindow, with a hardcoded --type=renderer parameter to appear legitimate.
FLATROOF [was] deployed under the name SystemUpdate to ~/Library/com.apple.iTunesCloud/SystemUpdate... ROOFDECK [was] dropped under the name iSync to ~/Library/com.apple.internal.ck/iSync... [and] uses a hardcoded --type=renderer parameter to make the implant process appear legitimate.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS ARM64 backdoor that executes shell commands, terminates processes, uploads files via Telegram, collects browser data, terminal histories, installed applications, process information, system profiles, and login.keychain-db, and assists deployment of ROOFDECK.
An ARM64 Rust macOS backdoor used for initial host data collection and secondary-payload deployment. It removes ROOFDECK's quarantine attribute and makes it executable to bypass Gatekeeper protections. FLATROOF supports shell-command execution, process termination, file upload via Telegram, and host identification. Its embedded Python harvester collects browser data, terminal histories, installed applications, process and system profiles, and login.keychain-db.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.