Researchers reported that OSX/Keydnap targeted macOS users with a two-stage malware chain built to steal credentials and maintain remote access. The threat was delivered in ZIP archives containing disguised Mach-O executables that used misleading file extensions and icons; once launched, the downloader installed a persistent backdoor named icloudsyncd and replaced itself with a decoy document to reduce suspicion. The malware also attempted privilege escalation by displaying a fake administrator prompt and established persistence through LaunchAgents.
The backdoor was designed to extract Keychain contents using code derived from the public Keychaindump proof of concept, giving attackers access to stored credentials. It communicated with command-and-control servers through onion.to Tor2Web proxies over HTTPS and sent RC4-encrypted POST data, while supporting remote updates, payload delivery, command execution, and self-removal. Researchers said the initial infection vector and total victim count were unclear, but the embedded decoy material suggested possible targeting of underground forum users or security researchers.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub commit in ESET's malware-research repository added a UPX patch for unpacking Keydnap samples. The commit, identified as dcbcf12 and attributed to marc-etienne, reflects new technical analysis material related to the malware.
ESET reported observing Keydnap backdoor version 1.3.5 in June 2016. The newer version indicated continued development of the malware shortly after the earlier 1.3.1 sample.
ESET reported that Keydnap backdoor version 1.3.1 was first seen in May 2016. This establishes the earliest explicitly dated observation of the malware family in the reference.
ESET published an analysis of OSX/Keydnap, a macOS malware family composed of a downloader and a persistent backdoor that steals keychain contents and maintains remote access. The report documented its disguised ZIP-based delivery, LaunchAgent persistence, fake privilege prompt, and Tor2Web-based command-and-control infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcewelivesecurity.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.