Researchers disclosed an active intrusion cluster dubbed JokerSpy that targeted a prominent Japan-based cryptocurrency exchange with a cross-platform toolkit spanning macOS, Linux, and Python-based malware. Elastic linked the operation to a self-signed Swift binary named xcc and a Python backdoor named sh.py, while Bitdefender identified related components including shared.dat; together, the malware supports command execution, file transfer, host profiling, payload delivery, and command-and-control beacons. Samples were observed in spring 2023, with investigators noting limited public visibility and signs that the toolkit was still only partially uncovered.
On macOS, the attackers used xcc to inspect permissions tied to Transparency, Consent, and Control (TCC), including Screen Recording, Accessibility, and Full Disk Access, and Elastic reported attempts to bypass TCC by replacing the TCC database. The intrusion also involved follow-on tooling such as the open-source enumeration utility Swiftbelt, plus staged non-native cryptographic libraries under /Users/shared/keybag that may have supported defense evasion or later exploitation. Investigators assessed that initial access likely came through a malicious or backdoored plugin or third-party dependency used by developer applications, indicating a supply-chain-style foothold aimed at deeper surveillance or post-compromise activity on macOS systems.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs disclosed an active macOS intrusion cluster tracked as REF9134 targeting a prominent Japan-based cryptocurrency exchange. The report linked the activity to the xcc and sh.py malware components, assessed initial access likely came via a malicious or backdoored plugin or third-party dependency, and released YARA detections.
Bitdefender disclosed a partially uncovered cross-platform malware toolkit dubbed JokerSpy, describing Python backdoors shared.dat and sh.py plus the macOS Swift binary xcc. The report said the toolkit appeared incomplete and suggested additional missing components likely existed.
A compromised macOS system generated a signature alert for MacOS.Hacktool.Swiftbelt, indicating use of the open-source enumeration tool Swiftbelt during the intrusion. Elastic linked this to post-exploitation activity delivered by the sh.py backdoor.
Researchers observed three non-native libraries placed in /Users/shared/keybag/: libcrypto.1.0.0.dylib, libncursesw.5.dylib, and libssl.1.0.0.dylib. Elastic assessed the staging may have supported defense evasion or future exploitation.
Bitdefender reported that the earliest referenced sample tied to the JokerSpy toolkit was anonymously uploaded to VirusTotal. This marked the earliest explicit date anchor for the malware samples discussed in the research.
Objective-See published a blog post titled "Ironing out (the macOS) details of a Smooth Operator (Part I)." The provided reference includes the publication date and title but no additional event details.
Bitdefender reported isolating a second xcc sample dated June 6 that contained only an x86 Mach-O binary. This added another concrete JokerSpy-related artifact to the known sample set.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcebitdefender.com
Open sourceobjective-see.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.