VORANT. Threat Intelligence Sign in Get the full feed

OSX/MaMi DNS hijacker targets macOS

medium threat

A new macOS malware dubbed OSX/MaMi hijacks DNS settings and installs a rogue root certificate to enable man-in-the-middle attacks.

Objective-See researcher Patrick Wardle analyzed a newly discovered macOS malware sample, named OSX/MaMi after an internal class name (SBMaMiSettings), after it was flagged on a MalwareBytes forum post. The unsigned Mach-O binary, hosted at regardens.info and undetected by all 59 VirusTotal engines at time of analysis, hijacks a victim's DNS servers (setting them to 82.163.143.135 and 82.163.142.137) and installs a malicious root CA certificate (CN=cloudguard.me) into the System keychain, enabling potential traffic interception and man-in-the-middle attacks. The malware also contains capabilities for taking screenshots, simulating mouse clicks, running AppleScript, downloading/uploading files, and executing arbitrary commands, though the researcher did not observe these being triggered during his limited analysis session.

The malware's configuration data revealed C2 reporting domains (honouncil.info, gorensin.info, squartera.info) used for activity/time reporting via HTTP, along with hardcoded placeholder domains. The researcher noted strong overlaps — identical DNS hijack IP ranges and the same malicious certificate — with a 2015 Windows malware called DNSUnlocker, suggesting OSX/MaMi may be a macOS port of that older Windows DNS hijacker with added platform-specific functionality. Infection vector remains unknown at time of writing, though phishing, fake security alerts, or social engineering are suspected.

Remediation guidance includes checking DNS settings via networksetup or System Preferences, inspecting the System keychain for the cloudguard.me certificate, and removing both if found; a full OS reinstall is recommended for thoroughness given the malware's capability to potentially deploy further payloads. No AV detection existed at publication time, and the author notes a forthcoming open-source firewall tool (LuLu) intended to detect the malware's network traffic.

Mentioned in this report

Malware DNSUnlockerOSX/MaMi

Source reporting: https://objective-see.org/blog/blog_0x26.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free