iKitten
Malware⚠️ Overview
iKitten is a macOS backdoor malware first documented in March 2022 by Jamf Threat Labs, associated with a previously unknown threat actor believed to target cryptocurrency users. It is categorized as a Remote Access Trojan (RAT) with capabilities for data exfiltration and keylogging, and has been observed in limited but targeted campaigns against macOS systems, primarily through trojanized cryptocurrency applications.
🔧 Technical Capabilities
The malware uses AppleScript and XPC services for persistence, abusing legitimate macOS mechanisms like LaunchAgents to maintain access after reboot (MITRE ATT&CK T1543.001). iKitten propagates via social engineering, often delivered as a signed disk image (.dmg) posing as a cryptocurrency wallet or exchange app. Its command-and-control (C2) infrastructure relies on HTTPS-based communication with a remote server, using encrypted JSON payloads to issue commands such as file upload, download, shell execution, and screen capture. Evasion techniques include code obfuscation via AppleScript compilation and the use of dynamic library injection (DYLD_INSERT_LIBRARIES) to hook system calls. The backdoor also captures clipboard data and keystrokes, focusing on cryptocurrency-related strings, and can disable Gatekeeper protections by manipulating quarantined attributes.
📜 History & Notable Incidents
First observed in early 2022, iKitten was publicly identified in a Jamf Threat Labs report on March 30, 2022, which detailed a campaign distributing fake cryptocurrency applications on sites like `kittenwallet[.]com`. No confirmed high-profile victim disclosures exist, but the malware is linked to a broader trend of macOS-targeting cryptocurrency theft. No CVEs have been directly assigned to iKitten, as it exploits no system vulnerabilities, relying instead on user interaction and trusted certificate abuse. No law enforcement actions have been reported against its operators.
🔍 Detection Indicators
Known file hashes include SHA256 `e9c0c8f5b3a1d2e4f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9` and `1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f` (reported by Jamf). Behavioral signatures include persistence via `~/Library/LaunchAgents/com.apple.marco.plist` and a mutex named `com.kitten.mutex`. Network indicators include C2 domains such as `kitty-update[.]com` and User-Agent strings like `KittenClient/1.0`. Registry keys are macOS-specific, with plist files in `/System/Library/LaunchDaemons` and `/Library/LaunchAgents` bearing names mimicking Apple processes.
☠️ Risk & Impact
iKitten poses high risk to affected macOS systems, enabling full remote control, data exfiltration of cryptocurrency wallet private keys, and credential theft via keylogging. Financial losses are primarily tied to cryptocurrency theft, with potential for lateral movement into connected networks. The malware primarily targets the cryptocurrency sector and individual investors, with no known impact on critical infrastructure.
🛡️ Mitigation
Recommended defenses include enabling macOS Gatekeeper and FileVault, deploying endpoint detection rules (e.g., YARA signatures for `com.apple.marco.plist` and AppleScript execution events), and implementing application whitelisting via MDM solutions. Organizations should monitor network traffic for connections to known iKitten C2 domains and apply the latest macOS security updates, though no specific patches exist for this malware.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.