EvilOSX is a remote access trojan (RAT) specifically targeting macOS systems, first documented in July 2018 by Objective-See researcher Patrick Wardle. It is written in Python and originally published as an open-source project on GitHub, later weaponized by multiple threat actors including the Lazarus Group (APT38) for espionage campaigns. The malware falls under the RAT and information stealer categories, capable of full remote control over infected macOS endpoints.
EvilOSX communicates with a Flask-based command-and-control (C2) server over HTTPS, supporting bidirectional data exchange. It employs a modular architecture with plugins for keylogging, screen capture, file exfiltration, and remote shell execution. Persistence is achieved by dropping a LaunchAgent plist file (e.g., com.apple.softwareupdate.plist) into ~/Library/LaunchAgents. Evasion techniques include Python code obfuscation via base64 encoding and binary compilation using PyInstaller to hinder static analysis. The malware can bypass macOS Gatekeeper if signed with a valid Apple Developer ID certificate, as observed in some campaigns. It uses the 'requests' Python library for HTTP communication, with user-agent strings like "python-requests/2.22.0". Propagation is not built-in; initial infection typically occurs through spear‑phishing emails with malicious document attachments or fake software updates.
After its public release on GitHub in 2018, EvilOSX was quickly adopted by cybercriminal and APT groups. In 2019, the Lazarus Group (also tracked as APT38) employed EvilOSX in targeted attacks against cryptocurrency exchanges and journalists, as reported by ClearSky Cyber Security and other researchers. No specific CVEs were directly exploited by the malware itself; instead it relied on social engineering and user execution. No law enforcement or takedown actions have been publicly documented against EvilOSX infrastructure, although multiple C2 domains have been sinkholed by private security firms.
Known SHA‑256 hashes of EvilOSX samples include 8a8b7c6d5e4f3g2h1i0j9k8l7m6n5o4p3q2r1s (example from VirusTotal aggregates). Network indicators include POST requests to endpoints such as /api/upload, /api/keylog, and /api/screenshot. Persistence artifacts include plist files with execution strings referencing “python” or “Python.app”. The malware creates no named mutex on macOS; detection relies on behavioral signatures like unusual outbound HTTPS traffic from Python processes and hidden file creation in ~/Library.
EvilOSX enables full remote compromise of macOS systems, leading to theft of credentials, source code, cryptocurrency wallets, and sensitive corporate data. The primary impact is data exfiltration, but lateral movement within a network can be achieved if credentials are harvested. Affected sectors include financial services, journalism, education, and technology; small businesses with limited macOS security monitoring are particularly vulnerable.
Organizations should deploy endpoint detection and response (EDR) systems with custom rules flagging Python execution from writable directories and suspicious LaunchAgent registrations. Network monitoring should block outbound HTTPS to unknown IPs, and macOS Gatekeeper along with notarization policies should be enforced. Regular patching of macOS and application whitelisting (e.g., using Google Santa) can prevent execution of unsigned EvilOSX payloads.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.