FinSpy macOS variant uses kernel rootkit
Objective-See's triage of a newly disclosed macOS FinSpy sample reveals a fake app dropper chain, local privilege escalation exploits, and an unsigned kernel-mode rootkit for process hiding.
Following Amnesty International's disclosure that FinFisher's FinSpy commercial spyware suite has previously undisclosed macOS and Linux variants, Objective-See performed a hands-on technical triage of the macOS sample (caglayan-macos.dmg). The malware disguises itself as an installer for a legitimate Turkish application (Çağlayan), using a bash script to launch a hidden backdoor installer (ARA0848.app) while a benign Adobe Air installer runs in the foreground to avoid raising suspicion.
The backdoor installer employs LLVM-based obfuscation, anti-debugging (ptrace denial), and VM-detection checks before attempting local privilege escalation via multiple exploits, including a known macOS <10.9/10 flaw and CVE-2015-5889. If exploitation fails, it falls back to prompting the user for admin credentials. Once root is obtained, it installs a persistent launch agent (logind.plist), a persistent implant (/private/etc/logind), and — notably — an unsigned kernel extension (logind.kext) that implements process-hiding rootkit functionality by unlinking target processes from the kernel's proc list. This kernel-mode capability is described as rare among public macOS malware samples. The kext is unsigned and thus non-functional on modern macOS versions enforcing kext signing, and the local privilege escalation exploits are patched in recent macOS releases, limiting the malware's practical impact to older/unpatched systems.
FinSpy has a documented history of use against human rights defenders, activists, journalists, and dissidents in countries including Bahrain, Ethiopia, Egypt, and the UAE. Objective-See notes their free tools (BlockBlock, KnockKnock, Process Monitor, File Monitor) can detect the malware's persistence and installation behavior without prior signature knowledge.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x4F.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free