Doctor Web disclosed BackDoor.Olyx, a Mac OS X backdoor that gives attackers covert remote access to infected machines. The malware contacts a command server and supports file creation, transfer, renaming, and deletion, while also downloading and executing additional payloads and running shell commands through /bin/bash. To stay resident, it creates files under /Library/Application Support/google/ and /Library/LaunchAgents/, then hides its original presence by moving its executable to a temporary folder.
Additional analysis linked Olyx, also referred to as Wolyx, to both a Mac Mach-O sample and a related Windows PE sample, indicating cross-platform tooling around the same operation. Public sample reporting identified the Mac file with MD5 93a9b55bb66d0ff80676232818d5952f and a Windows executable with MD5 f65fbeb945348ad2e1a123ef5cee65d3, while observed network traffic was tied to IP 121.254.173.57 in South Korea. Doctor Web said detection for BackDoor.Olyx had been added to its virus database and urged Mac users to keep protections updated and scan systems regularly.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A Windows executable associated with Olyx/Wolyx, named "Video-Current events 2009 July 5.exe," was shown in the referenced analysis content with a submission timestamp of 2011-07-27 05:00:39 UTC. The sample was detected by multiple antivirus engines and linked in the post to Ghostnet-style backdoor activity.
On June 22, 2011, Doctor Web announced the discovery of BackDoor.Olyx, a Mac OS X backdoor that lets attackers remotely control infected systems, manipulate files, download and execute payloads, and run shell commands. The report also described its persistence mechanisms and noted that Dr.Web added detection for the malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.