pkgunpack is a custom macOS cryptographic utility used in the MacSync malware-as-a-service infection chain. It generates Curve25519 ECDH key pairs and derives shared-secret-based key material to unwrap server-provided payload-decryption keys using AES-GCM. MacSync uses the utility to decrypt and access later-stage stealer and backdoor modules. The utility clears buffers containing cryptographic keys and decrypted data after processing, hindering forensic recovery and dynamic analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malicious utility used by MacSync scripts to generate Curve25519 ECDH key pairs and decrypt server-delivered payload encryption keys and AES-GCM-encrypted malicious modules.
Custom malicious-chain utility used by MacSync to generate Curve25519 key pairs, derive an ECDH shared secret, unwrap AES-GCM payload keys, and decrypt downloaded infostealer and backdoor modules.
Custom MacSync utility that generates Curve25519 ECDH key pairs and decrypts server-wrapped payload keys and AES-GCM-encrypted malicious modules. It clears key and data buffers after use, likely to impede forensic collection and dynamic analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.