Objective-See recaps 2022 macOS malware
Objective-See's annual roundup details SysJoker, DazzleSpy, CoinMiner, and Gimmick—new macOS malware families discovered throughout 2022.
This report is Objective-See's seventh annual comprehensive review of new macOS malware observed during 2022, compiling analysis and IOCs for multiple distinct families with sample downloads for researcher use. Covered specimens include SysJoker, a cross-platform backdoor first found on a Linux web server and later identified with a macOS variant possibly distributed via infected npm packages; DazzleSpy, a fully-featured cyber-espionage implant deployed through a watering-hole attack exploiting a WebKit vulnerability and a privilege-escalation flaw against Hong Kong pro-democracy protesters; CoinMiner, a cryptocurrency miner bundled in trojanized Adobe Photoshop/Zii disk images that uses a modified XMRig binary and I2P tunneling to obscure its network traffic; and Gimmick, a multi-platform espionage implant attributed by Volexity to the Chinese threat actor Storm Cloud, which abuses cloud services like Google Drive for command-and-control.
Each malware family is detailed with infection vectors, persistence mechanisms (primarily via LaunchAgents/LaunchDaemons), and capabilities ranging from simple backdoor functionality to full remote-control cyber-espionage tooling. The piece functions as a reference/threat-intel compilation rather than reporting a single new incident, aggregating previously-published vendor research (Intezer, ESET, TrendMicro, Volexity, Google TAG) into one consolidated resource with IOCs and technical analysis for defenders and researchers.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x71.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free