# Objective-See recaps 2022 macOS malware

Published: 2023-01-01 · Severity: medium · Sectors: education, technology
Canonical: https://vorant.io/reports/24c8c878-35ee-59ae-8a5d-f3a3990d9878/objective-see-recaps-2022-macos-malware

> Objective-See's annual roundup details SysJoker, DazzleSpy, CoinMiner, and Gimmick—new macOS malware families discovered throughout 2022.

This report is Objective-See's seventh annual comprehensive review of new macOS malware observed during 2022, compiling analysis and IOCs for multiple distinct families with sample downloads for researcher use. Covered specimens include SysJoker, a cross-platform backdoor first found on a Linux web server and later identified with a macOS variant possibly distributed via infected npm packages; DazzleSpy, a fully-featured cyber-espionage implant deployed through a watering-hole attack exploiting a WebKit vulnerability and a privilege-escalation flaw against Hong Kong pro-democracy protesters; CoinMiner, a cryptocurrency miner bundled in trojanized Adobe Photoshop/Zii disk images that uses a modified XMRig binary and I2P tunneling to obscure its network traffic; and Gimmick, a multi-platform espionage implant attributed by Volexity to the Chinese threat actor Storm Cloud, which abuses cloud services like Google Drive for command-and-control.

Each malware family is detailed with infection vectors, persistence mechanisms (primarily via LaunchAgents/LaunchDaemons), and capabilities ranging from simple backdoor functionality to full remote-control cyber-espionage tooling. The piece functions as a reference/threat-intel compilation rather than reporting a single new incident, aggregating previously-published vendor research (Intezer, ESET, TrendMicro, Volexity, Google TAG) into one consolidated resource with IOCs and technical analysis for defenders and researchers.

## Mentioned in this report

- Vulnerabilities: CVE-2019-8526 (KEV), CVE-2021-1789 (KEV), CVE-2021-30869 (KEV)
- Threat actors: Storm Cloud
- Malware: Coinminer, DazzleSpy, GIMMICK, SysJoker

Source reporting: https://objective-see.org/blog/blog_0x71.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/24c8c878-35ee-59ae-8a5d-f3a3990d9878/objective-see-recaps-2022-macos-malware.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
