I see what you did there: A look at the CloudMensis macOS spyware
2022-07-19 • ESET •
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
ESET analyzed CloudMensis, a macOS spyware family discovered in April 2022 that uses public cloud storage services such as pCloud, Yandex Disk, and Dropbox for command exchange and data exfiltration. The malware follows a two-stage flow in which a downloader installs a more capable spy agent as a system-wide daemon after code execution and administrative privileges are obtained. The second stage collects documents, keystrokes, screenshots, email attachments, and other sensitive data from compromised Macs while maintaining encrypted local configuration. ESET also found legacy Safari exploit cleanup code tied to patched 2017 vulnerabilities, suggesting the toolset may have been in use for years even though the initial compromise vector remained unknown.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0aa94d8df1840d734f25426926e5295… | 2022-07-19 | 2022-07-19 |
| HASH | d7bf702f56ca53140f4f03b590e9afc… | 2022-07-19 | 2022-07-19 |
| HASH | c3e48c2a2d43c752121e55b909fc705… | 2022-07-19 | 2022-07-19 |