Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack
2023-06-16 • Bitdefender •
Bitdefender documented early fragments of a larger macOS and cross-platform toolkit: Python backdoors named shared.dat and sh.py plus a macOS Swift binary called xcc. shared.dat uses ROT13-obfuscated paths and a GITHUB_REQ/GITHUB_RES packet format to collect host, network, and process information, execute commands, and download OS-specific payloads such as an AppleAccount archive on macOS or compiled code on Linux. sh.py stores configuration in ~/Public/Safari/sar.dat, supports command execution, file upload and download, deletion, configuration changes, and Python code execution, and can rotate between configured C2 URLs. The xcc component targets macOS 12+, checks privacy and user-state permissions before likely spyware use, and indicates the observed files were part of a broader multi-stage intrusion set.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6d3eff4e029db9d7b8dc076cfed5e23… | 2023-06-16 | 2024-04-11 |
| URL | https://www.git-hub.me/view.php | 2023-06-16 | 2023-11-14 |
| HASH | 39bbc16028fd46bf4ddad49c2143950… | 2023-06-16 | 2023-07-19 |
| HASH | 951039bf66cdf436c240ef206ef7356… | 2023-06-16 | 2023-07-19 |
| HASH | aa951c053baf011d08f3a60a10c1d09… | 2023-06-16 | 2023-07-19 |
| HASH | 5fe1790667ee5085e73b054566d548e… | 2023-06-16 | 2023-07-19 |
| HASH | d895075057e491b34b0f8c0392b44e4… | 2023-06-16 | 2023-07-19 |