The FruitFly macOS backdoor operated undetected for years, giving attackers covert access to infected Macs through a malware set built largely from Perl scripts with helper components including a Mach-O binary and a Java class. The malware could execute commands, capture screenshots, log keystrokes, access webcams, collect system information, and enumerate other devices on the same network before exfiltrating data to command-and-control infrastructure. Research by Patrick Wardle on a newer variant found decrypted backup domains, and after one domain was registered, nearly 400 infected Macs checked in, most of them from home networks in the United States.
The campaign came under wider scrutiny after Case Western Reserve University was alerted to an infection and identified more than 100 additional compromised systems, prompting FBI involvement. Malwarebytes publicly disclosed FruitFly after finding earlier samples on a small number of Macs, and Apple subsequently updated macOS to detect that version. Investigators later tied the operation to Phillip Roman Durachinsky, raided locations linked to him over fears evidence could be deleted, and ultimately collected about 20 million files, identified thousands of victims, and uncovered child sexual abuse material; Durachinsky was arrested and later indicted on 16 counts.

Pull IOCs and campaign context straight into your stack.
14 events from the most recent confirmed update back to the earliest known activity.
Prosecutors filed their response to the defense motion to suppress evidence.
The defense filed a motion to suppress evidence, arguing improper seizure and seeking to exclude laptop-derived evidence and a confession.
Phillip Roman Durachinsky was indicted on 16 counts, including charges related to damaging and accessing protected computers, child pornography production, wire fraud, aggravated identity theft, unauthorized access to a government computer, and illegal wiretapping.
The FBI issued a FLASH containing FruitFly malware details.
Phillip Roman Durachinsky was arrested in connection with the FruitFly investigation.
A warrant authorizing access to the seized data was signed at 4:40 a.m. EST. Investigators later collected about 20 million files, identified thousands of victims, and found child pornography in the evidence.
Later the same day as the public disclosure, the FBI raided the home of Durachinsky's parents because of concerns that evidence might be deleted. Agents seized a powered-on laptop that was allegedly being remotely controlled, along with numerous hard drives.
An MRT update was released in connection with FruitFly on the same day as the public disclosure, adding detection for the earlier malware variant.
Malwarebytes publicly released its discovery of FruitFly. The earlier variant had been found infecting four Macs, and Apple also updated macOS to automatically detect that earlier malware.
Investigators identified Phillip Roman Durachinsky as a suspect in the FruitFly case, aided by evidence including an IP address tied to the malware and access to an alumni email account.
After the university identified additional infected systems, the FBI was contacted about the FruitFly investigation.
Case Western Reserve University was notified of a FruitFly infection and subsequently found more than 100 additional infected systems. The compromised computers had reportedly been infected for several years.
Patrick Wardle authored a 2017 Virus Bulletin paper analyzing the newer OSX/FruitFly.B variant by redirecting it to a custom command-and-control server. The paper disclosed technical details including its persistence mechanism, C2 infrastructure, use of TCP port 22, and remote-control capabilities such as screen capture, file operations, mouse movement, and keyboard simulation.
Patrick Wardle decrypted hardcoded backup domains in a newer FruitFly variant and registered one that was still available. Within two days, nearly 400 infected Macs connected to his server, most appearing to be home systems in the United States.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourceobjective-see.com
Open sourcevirusbulletin.com
Open sourceobjective-see.com
Open sourceobjectivebythesea.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.