ESET detailed CloudMensis, a macOS spyware family designed for targeted espionage that collects sensitive information from infected systems and exfiltrates it through public cloud storage services. The malware was described as a relatively unsophisticated but effective implant that can steal documents, keystrokes, screen captures, email data, and other files of interest, while also issuing commands and retrieving additional payloads from attacker-controlled cloud accounts.
Researchers said CloudMensis relied on cloud-based infrastructure for command-and-control and data theft, a design that helped blend malicious traffic with legitimate online services and complicated detection. The report linked the operation to a limited number of victims and assessed it as part of a broader trend of macOS-focused surveillance activity, underscoring that Apple systems remain active targets for spyware operators despite the platform's reputation for stronger security.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET publicly released a report detailing CloudMensis, a macOS spyware threat, including its capabilities and behavior. The reference indicates this disclosure occurred when the article was published.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.