# OSX.Mokes.B backdoor hits crypto exchange staff

Published: 2026-08-02 · Severity: high · Sectors: financial-services
Canonical: https://vorant.io/reports/ebbffad9-70ac-57ff-9826-418e70ad9940/osx-mokes-b-backdoor-hits-crypto-exchange-staff

> A new Mokes malware variant, dropped alongside OSX.Netwire via a Firefox zero-day, backdoored Mac systems at cryptocurrency exchanges and evaded all AV engines.

Objective-See researchers analyzed a second macOS malware sample used in a campaign that leveraged a Firefox zero-day to target employees at cryptocurrency exchanges. The first payload, OSX.Netwire.A, was covered in earlier posts; this article details the second payload, an unsigned 13MB Mach-O binary that was undetected by every AV engine on VirusTotal at time of submission. Static and dynamic analysis revealed the malware installs itself under randomized names (e.g., quicklookd, storeaccountd) into locations like ~/Library/Dropbox/, persists via a LaunchAgent plist with RunAtLoad, and beacons out to a hardcoded C2 IP (185.49.69.210).

The analyst, cross-referencing strings, embedded Objective-C classes, and file-search/exfiltration constants, determined the sample shares extensive code and behavioral overlap with OSX.Mokes, a cross-platform backdoor first documented by Kaspersky in 2016. Shared traits include identical file-search constants for Office documents, matching temporary file naming conventions for screenshots/audio/keylogs/data (.sst/.aat/.kkt/.ddt), AVFoundation-based webcam/audio capture capability, and similar installation naming pairs. Based on this, the researcher designates the new sample OSX.Mokes.B, a variant of the original Mokes backdoor rather than a wholly new family.

The piece emphasizes that despite close lineage to a well-documented 2016 backdoor, the new variant evaded all VirusTotal AV signatures, reinforcing the value of behavior-based detection tools (KnockKnock, BlockBlock, LuLu, OverSight) that can generically flag persistence, C2 communication, and audio/video capture without prior signature knowledge.

## Mentioned in this report

- Malware: OSX.Mokes.B, OSX.Netwire.A

Source reporting: https://objective-see.org/blog/blog_0x45.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ebbffad9-70ac-57ff-9826-418e70ad9940/osx-mokes-b-backdoor-hits-crypto-exchange-staff.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
