# 2017 Mac Malware Roundup: Proton, XAgent, Dok

Published: 2026-08-02 · Severity: high
Canonical: https://vorant.io/reports/06be8857-1008-550b-9d04-39a1e901edad/2017-mac-malware-roundup-proton-xagent-dok

> Objective-See recaps four 2017 macOS threats—Proton, APT28's XAgent/Komplex, FileCoder ransomware, and the Dok banking trojan—spread via supply-chain and phishing attacks.

This retrospective from Objective-See details several distinct macOS malware families active throughout 2017. OSX/Proton, a feature-complete backdoor sold as malware-as-a-service, spread through supply-chain compromises of legitimate developer sites (HandBrake mirror, Eltima applications) and a fake Symantec blog, stealing browser credentials, keychains, 1Password vaults, and GnuPG keys while persisting via Launch Agents. Notably, variant C was signed with a legitimate (later revoked) Apple Developer ID to bypass Gatekeeper.

The post also examines OSX/XAgent, attributed to APT28/Sofacy (Fancy Bear), a fully-featured second-stage macOS implant delivered via the OSX/Komplex downloader and capable of keylogging, screen capture, app injection, and iOS backup discovery; it appears to avoid persistence to reduce detection risk, relying instead on Komplex's Launch Agent. Additionally, FileCoder (FindZip/Patcher) ransomware, distributed via pirated-software torrents, encrypts victim files with a password-protected zip using a key that is never transmitted to the attacker—rendering ransom payment useless, though a known-plaintext attack allows recovery. Finally, OSX/Dok, a macOS port of the Retefe banking trojan, was delivered via a coordinated phishing campaign against German users and installs a malicious proxy (routed through Tor) to perform MitM attacks on victim web traffic for banking credential theft.

## Mentioned in this report

- Threat actors: APT28
- Malware: FileCoder (FindZip/Patcher), OSX/Dok, OSX/Komplex, OSX/Proton, OSX/XAgent

Source reporting: https://objective-see.org/blog/blog_0x25.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/06be8857-1008-550b-9d04-39a1e901edad/2017-mac-malware-roundup-proton-xagent-dok.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
