Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ROOFDECK acts as a more sophisticated backdoor with broader reconnaissance and lateral movement capabilities. It was deployed as iSync and later as a stripped loginwindow executable.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
FLATROOF was deployed as SystemUpdate; ROOFDECK was deployed as iSync and later loginwindow, with a hardcoded --type=renderer parameter to appear legitimate.
FLATROOF [was] deployed under the name SystemUpdate to ~/Library/com.apple.iTunesCloud/SystemUpdate... ROOFDECK [was] dropped under the name iSync to ~/Library/com.apple.internal.ck/iSync... [and] uses a hardcoded --type=renderer parameter to make the implant process appear legitimate.
FLATROOF obtains a running-process snapshot via ps aux; ROOFDECK implements process listing through proc_listallpids, proc_pidinfo, and proc_pid_rusage.
TraderTraitor used the backdoors to collect API keys from the organization... ROOFDECK find [performs] recursive file search... used to locate high-value data (wallets, keys, docs) for exfiltration.
ROOFDECK supports... C2... The C2 endpoint is hardcoded as /app_version. Polling for commands is done via HTTPS... FLATROOF... exfiltrate[s] them over Telegram using a built-in Telegram bot token.
Upon first execution, it pulls live Nostr relays... then searches the relays for an operator’s profile on the Nostr network... When found, it reads the website field of the profile and uses that as its C2 URL.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust ARM64 macOS backdoor that establishes persistence through LaunchAgents, discovers C2 through Nostr relays and a configured attacker profile, verifies signed commands, executes commands and shells, transfers files, performs host and filesystem reconnaissance, searches for high-value data, and accesses the clipboard. It can download updates, manage tasks, and self-destruct.
An ARM64 Rust macOS backdoor used after initial foothold establishment. It uses Nostr-profile dead drops to resolve C2 infrastructure, maintains LaunchAgent persistence, verifies attacker-signed commands using an embedded public key, and uses pinned TLS for HTTPS or WebSocket communications. It supports interactive and reverse shells, arbitrary command execution, file discovery and transfer, host/process/filesystem reconnaissance, clipboard access, payload download, self-update, encrypted archive creation, and self-deletion. A stripped ROOFDECK variant was deployed as loginwindow and replaced the earlier FLATROOF and ROOFDECK binaries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.