# FinSpy macOS variant uses kernel rootkit

Published: 2020-09-26 · Severity: medium · Sectors: government-national
Canonical: https://vorant.io/reports/afdfab54-cbab-5bca-ba55-43996dd366b7/finspy-macos-variant-uses-kernel-rootkit

> Objective-See's triage of a newly disclosed macOS FinSpy sample reveals a fake app dropper chain, local privilege escalation exploits, and an unsigned kernel-mode rootkit for process hiding.

Following Amnesty International's disclosure that FinFisher's FinSpy commercial spyware suite has previously undisclosed macOS and Linux variants, Objective-See performed a hands-on technical triage of the macOS sample (caglayan-macos.dmg). The malware disguises itself as an installer for a legitimate Turkish application (Çağlayan), using a bash script to launch a hidden backdoor installer (ARA0848.app) while a benign Adobe Air installer runs in the foreground to avoid raising suspicion.

The backdoor installer employs LLVM-based obfuscation, anti-debugging (ptrace denial), and VM-detection checks before attempting local privilege escalation via multiple exploits, including a known macOS <10.9/10 flaw and CVE-2015-5889. If exploitation fails, it falls back to prompting the user for admin credentials. Once root is obtained, it installs a persistent launch agent (logind.plist), a persistent implant (/private/etc/logind), and — notably — an unsigned kernel extension (logind.kext) that implements process-hiding rootkit functionality by unlinking target processes from the kernel's proc list. This kernel-mode capability is described as rare among public macOS malware samples. The kext is unsigned and thus non-functional on modern macOS versions enforcing kext signing, and the local privilege escalation exploits are patched in recent macOS releases, limiting the malware's practical impact to older/unpatched systems.

FinSpy has a documented history of use against human rights defenders, activists, journalists, and dissidents in countries including Bahrain, Ethiopia, Egypt, and the UAE. Objective-See notes their free tools (BlockBlock, KnockKnock, Process Monitor, File Monitor) can detect the malware's persistence and installation behavior without prior signature knowledge.

## Mentioned in this report

- Vulnerabilities: CVE-2015-5889 (weaponized)
- Threat actors: FinFisher
- Malware: FinSpy, OSX.FinSpy

Source reporting: https://objective-see.org/blog/blog_0x4F.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/afdfab54-cbab-5bca-ba55-43996dd366b7/finspy-macos-variant-uses-kernel-rootkit.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
