# Objective-See recaps 2018 Mac malware crop

Published: 2026-08-02 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/7ae38393-7a48-5c3e-8689-34a7bb0a988e/objective-see-recaps-2018-mac-malware-crop

> Objective-See's annual roundup details a year of new macOS malware including DNS-hijacking, cryptominers, RATs, and adware droppers.

This Objective-See blog post is an annual retrospective cataloguing the new macOS malware families that emerged throughout 2018, describing each specimen's infection vector, persistence mechanism, and capabilities. The families covered range from commodity threats like cryptominers (CreativeUpdate, PPMiner) and adware droppers (Shlayer) to more capable backdoors and RATs (CrossRAT, ColdRoot, Dummy, Calisto) and a DNS-hijacking trojan (MaMi) that installs a rogue root certificate to enable man-in-the-middle traffic interception.

Most infections relied on social engineering — malicious popups, trojanized downloads from compromised or lookalike sites (MacUpdate.com, fake cdn-mozilla.net), BitTorrent-delivered fake Flash updates, and direct victim self-infection via crypto-community Discord/Slack impersonation. Persistence across nearly all samples was achieved through standard macOS LaunchDaemon/LaunchAgent plists set to RunAtLoad, a technique Objective-See's BlockBlock tool is shown detecting repeatedly. CrossRAT stands out as part of a broader cyber-espionage campaign (Dark Caracal) attributed by EFF/Lookout research, while the remaining families are largely opportunistic commodity malware focused on cryptomining, adware monetization, or general backdoor access.

Overall severity is low: this is a historical/informational compilation of already-disclosed 2018 malware rather than a report of new or ongoing active exploitation. No CVEs are involved, and most described threats are low-sophistication, opportunistic tools relying on user interaction rather than technical exploitation.

## Mentioned in this report

- Threat actors: Dark Caracal
- Malware: Coldroot, CrossRAT, OSX.Calisto, OSX.CreativeUpdate, OSX.Dummy, OSX.MaMi, OSX.PPMiner, OSX.Shlayer, XMRIG

Source reporting: https://objective-see.org/blog/blog_0x3C.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7ae38393-7a48-5c3e-8689-34a7bb0a988e/objective-see-recaps-2018-mac-malware-crop.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
