A compromised HandBrake mirror server distributed a trojanized macOS installer that infected users who downloaded the application during a limited exposure window. The malicious HandBrake.app unpacked a hidden payload, launched it from a temporary path, and displayed a fake authentication prompt to steal the user’s password. Researchers identified the payload as Proton.B, a new variant of the OSX/Proton remote access trojan, which then installed itself persistently as activity_agent.app using ~/Library/LaunchAgents/fr.handbrake.activity_agent.plist and related files under ~/Library/RenderFiles/.
Once installed, Proton.B used the stolen credentials to gain elevated privileges with sudo, altered the tty_tickets setting, and decrypted embedded resources before checking connectivity and time sources. The malware harvested browser data, macOS keychains, GnuPG material, and 1Password vaults, compressed the stolen information into ZIP archives, and exfiltrated it to api.handbrake.biz. It also attempted to evade analysis by terminating tools such as Terminal and Wireshark and deleting system logs, while early defenses were limited because Apple’s initial XProtect coverage relied on a simple SHA-1 hash of the trojanized binary and the samples initially showed little or no antivirus detection.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
A later technical analysis described Proton.B's behavior in depth, including social-engineering for the user's password, sudo abuse, persistence, theft of browser data, keychains, GnuPG material, and 1Password vaults, and exfiltration of stolen archives to api.handbrake.biz.
A compromised HandBrake mirror download server distributed a trojanized macOS disk image to users. HandBrake later identified the exposure window as running from 2017-05-02 14:30 UTC until 2017-05-06 11:00 UTC.
After the HandBrake incident, Apple released an XProtect rule named XProtect_OSX_Proton_B to detect the trojaned HandBrake binary. The analysis noted the protection relied on a single SHA-1 hash and could be bypassed by modifying the file.
Analysis of the trojanized HandBrake installer showed it unpacked a hidden payload, used a fake authentication prompt to steal credentials, and installed itself persistently as activity_agent.app via a LaunchAgent. The malware was assessed as a new OSX/Proton variant referred to as Proton.B.
HandBrake published a security alert stating that its mirror download server had been compromised and warning Mac users who downloaded during the affected window to verify hashes and check for Trojan infection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.