#CloudMensis

Incident/Operation

2022-07-19 • I see what you did there: A look at the CloudMensis macOS spyware

CloudMensis is a two-stage macOS spyware family discovered in April 2022 and attributed in later analysis to the North Korean actor APT37, also known as ScarCruft. Developed in Objective-C for both Intel and Apple silicon, it uses public cloud-storage services to retrieve components and exchange data with its operators. Its espionage functions include exfiltrating documents and keystrokes, capturing screens, and executing commands; observed samples also manipulated the macOS privacy database to grant screen-capture and FaceTime permissions and load an attacker-controlled configuration.

Tagged Reports

« Back