I see what you did there: A look at the CloudMensis macOS spyware

2022-07-19 • ESET •

https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/

Thumbnail for I see what you did there: A look at the CloudMensis macOS spyware

ESET analyzed CloudMensis, a macOS spyware family discovered in April 2022 that uses public cloud storage services such as pCloud, Yandex Disk, and Dropbox for command exchange and data exfiltration. The malware follows a two-stage flow in which a downloader installs a more capable spy agent as a system-wide daemon after code execution and administrative privileges are obtained. The second stage collects documents, keystrokes, screenshots, email attachments, and other sensitive data from compromised Macs while maintaining encrypted local configuration. ESET also found legacy Safari exploit cleanup code tied to patched 2017 vulnerabilities, suggesting the toolset may have been in use for years even though the initial compromise vector remained unknown.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 317ce26cae14dc9a5e4d4667f00fee7… 2022-07-19 2024-04-11
HASH b8a61adccefb13b7058e47edcd10a12… 2022-07-19 2024-04-11
HASH 273633eee4776aef40904124ed1722a… 2022-07-19 2022-07-19

Related Reports

« Back