VORANT. Threat Intelligence Sign in Get the full feed

Objective-See recaps 2018 Mac malware crop

low threat technology

Objective-See's annual roundup details a year of new macOS malware including DNS-hijacking, cryptominers, RATs, and adware droppers.

This Objective-See blog post is an annual retrospective cataloguing the new macOS malware families that emerged throughout 2018, describing each specimen's infection vector, persistence mechanism, and capabilities. The families covered range from commodity threats like cryptominers (CreativeUpdate, PPMiner) and adware droppers (Shlayer) to more capable backdoors and RATs (CrossRAT, ColdRoot, Dummy, Calisto) and a DNS-hijacking trojan (MaMi) that installs a rogue root certificate to enable man-in-the-middle traffic interception.

Most infections relied on social engineering — malicious popups, trojanized downloads from compromised or lookalike sites (MacUpdate.com, fake cdn-mozilla.net), BitTorrent-delivered fake Flash updates, and direct victim self-infection via crypto-community Discord/Slack impersonation. Persistence across nearly all samples was achieved through standard macOS LaunchDaemon/LaunchAgent plists set to RunAtLoad, a technique Objective-See's BlockBlock tool is shown detecting repeatedly. CrossRAT stands out as part of a broader cyber-espionage campaign (Dark Caracal) attributed by EFF/Lookout research, while the remaining families are largely opportunistic commodity malware focused on cryptomining, adware monetization, or general backdoor access.

Overall severity is low: this is a historical/informational compilation of already-disclosed 2018 malware rather than a report of new or ongoing active exploitation. No CVEs are involved, and most described threats are low-sophistication, opportunistic tools relying on user interaction rather than technical exploitation.

Mentioned in this report

Threat actors Dark Caracal
Malware ColdrootCrossRATOSX.CalistoOSX.CreativeUpdateOSX.DummyOSX.MaMiOSX.PPMinerOSX.ShlayerXMRIG

Source reporting: https://objective-see.org/blog/blog_0x3C.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free