I see what you did there: A look at the CloudMensis macOS spyware

2022-07-19 ESET

https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/

Thumbnail for I see what you did there: A look at the CloudMensis macOS spyware

ESET analyzed CloudMensis, a macOS spyware family discovered in April 2022 that uses public cloud storage services such as pCloud, Yandex Disk, and Dropbox for command exchange and data exfiltration. The malware follows a two-stage flow in which a downloader installs a more capable spy agent as a system-wide daemon after code execution and administrative privileges are obtained. The second stage collects documents, keystrokes, screenshots, email attachments, and other sensitive data from compromised Macs while maintaining encrypted local configuration. ESET also found legacy Safari exploit cleanup code tied to patched 2017 vulnerabilities, suggesting the toolset may have been in use for years even though the initial compromise vector remained unknown.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0aa94d8df1840d734f25426926e5295… 2022-07-19 2022-07-19
HASH d7bf702f56ca53140f4f03b590e9afc… 2022-07-19 2022-07-19
HASH c3e48c2a2d43c752121e55b909fc705… 2022-07-19 2022-07-19

Related Reports

« Back