VORANT. Threat Intelligence Sign in Get the full feed

WindShift APT's macOS backdoor OSX.WindTail exposed

high threat government-nationalinfrastructure

Objective-See publicly released and analyzed samples of OSX.WindTail, the macOS backdoor used by WindShift APT against Middle Eastern government targets.

Building on prior research by Taha Karim (DarkMatter) presented at Hack in the Box Singapore, Objective-See researchers located and publicly shared four previously-unreleased samples of OSX.WindTail on VirusTotal, confirming them as variants of the WindShift APT group's macOS implant. The malware masquerades as Microsoft Office documents, uses revoked Apple developer certificates, and abuses the LSSharedFileListInsertItemURL API to persist as a login item. Notably, three of the four samples were undetected by any anti-virus engine on VirusTotal at time of writing, despite Apple having revoked the signing certificates - suggesting a gap in threat-intel sharing between Apple and the AV community.

Technical analysis revealed the implant decrypts strings and C2 configuration using a hardcoded AES key identical to one previously shown in Karim's research, strongly tying the new samples to WindShift. Decrypted strings reference file extensions of espionage interest (doc, pdf, db) and two C2 domains, flux2key.com and string2me.com, both previously identified by Karim as WindShift infrastructure. At the time of analysis both domains were offline, limiting dynamic observation of C2 command execution, but static analysis suggests standard backdoor capabilities including file exfiltration and remote command execution.

WindShift is described as a highly-targeted cyber-espionage group focused on individuals in government departments and critical infrastructure organizations in the Middle East. The blog notes that Objective-See's free tools (BlockBlock, KnockKnock) can heuristically detect this malware absent signature-based AV coverage, and provides manual indicators (suspicious Login Items, Office-icon apps with invalid signatures in ~/Library/) for self-triage.

Mentioned in this report

Threat actors Windshift
Malware OSX.WindTailOSX.WindTape

Source reporting: https://objective-see.org/blog/blog_0x3B.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free