VORANT. Threat Intelligence Sign in Get the full feed

Objective-See recaps 2022 macOS malware

medium threat educationtechnology

Objective-See's annual roundup details SysJoker, DazzleSpy, CoinMiner, and Gimmick—new macOS malware families discovered throughout 2022.

This report is Objective-See's seventh annual comprehensive review of new macOS malware observed during 2022, compiling analysis and IOCs for multiple distinct families with sample downloads for researcher use. Covered specimens include SysJoker, a cross-platform backdoor first found on a Linux web server and later identified with a macOS variant possibly distributed via infected npm packages; DazzleSpy, a fully-featured cyber-espionage implant deployed through a watering-hole attack exploiting a WebKit vulnerability and a privilege-escalation flaw against Hong Kong pro-democracy protesters; CoinMiner, a cryptocurrency miner bundled in trojanized Adobe Photoshop/Zii disk images that uses a modified XMRig binary and I2P tunneling to obscure its network traffic; and Gimmick, a multi-platform espionage implant attributed by Volexity to the Chinese threat actor Storm Cloud, which abuses cloud services like Google Drive for command-and-control.

Each malware family is detailed with infection vectors, persistence mechanisms (primarily via LaunchAgents/LaunchDaemons), and capabilities ranging from simple backdoor functionality to full remote-control cyber-espionage tooling. The piece functions as a reference/threat-intel compilation rather than reporting a single new incident, aggregating previously-published vendor research (Intezer, ESET, TrendMicro, Volexity, Google TAG) into one consolidated resource with IOCs and technical analysis for defenders and researchers.

Mentioned in this report

Vulnerabilities CVE-2019-8526KEVCVE-2021-1789KEVCVE-2021-30869KEV
Threat actors Storm Cloud
Malware CoinminerDazzleSpyGIMMICKSysJoker

Source reporting: https://objective-see.org/blog/blog_0x71.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free