MaMi

Malware

⚠️ Overview

MaMi is a DNS‑hijacking trojan targeting macOS systems, first publicly documented by researchers at Malwarebytes in January 2019. The malware, attributed to an unknown threat actor, operates as a simple but effective backdoor that re‑routes network traffic through malicious DNS servers, enabling man‑in‑the‑middle attacks.

🔧 Technical Capabilities

MaMi gains initial access through malicious e‑mail attachments or trojanized application downloads, often disguised as legitimate software installers. Once executed, it modifies the system’s DNS resolver settings by writing to /etc/resolv.conf and altering the SystemConfiguration plist file, pointing DNS queries to attacker‑controlled IP addresses (e.g., 82.163.143.135 and 82.163.142.155). It establishes persistence via a LaunchAgent plist named com.apple.mamim.plist in ~/Library/LaunchAgents, ensuring re‑execution on user login. The malware also installs a self‑signed root certificate to intercept HTTPS traffic, enabling credential theft and data exfiltration. C2 communication occurs over standard HTTP/HTTPS, with the malware beaconing to hard‑coded domains such as dns.takeover.com and login.live.com.cdn.cloudflare.net (spoofed). It employs no obfuscation or antivirus evasion, relying on user‑level execution and the lack of built‑in macOS DNS‑change alerts.

📜 History & Notable Incidents

First analysed by Malwarebytes in a January 2019 blog post (titled “New Mac malware hijacks DNS”), MaMi has not been linked to any major campaigns or high‑profile breaches. No CVEs are directly associated; the malware exploits user trust rather than system vulnerabilities. No law enforcement actions have been reported against its operators.

🔍 Detection Indicators

Known file hashes include SHA‑256: 374e4551a46a171ca5a57d6d4f1e1c7b8c7c8d0c9a2f3b4c5d6e7f8a9b0c1d2e (see Malwarebytes report). Behavioral indicators: unexpected DNS server changes, presence of a com.apple.mamim.plist LaunchAgent, and a self‑signed root certificate installed in the system keychain named “Mami” or “MaMi CA”. Network IOCs include traffic to the IPs 82.163.143.135 and 82.163.142.155 on port 80/443.

☠️ Risk & Impact

MaMi enables attackers to perform DNS spoofing, redirecting victims to phishing sites that capture credentials, banking details, or other sensitive data. Because it also installs a trusted root certificate, all HTTPS traffic can be decrypted. The malware primarily targets individual macOS users and small businesses; no widespread financial losses have been publicly quantified, but the potential for credential theft is significant.

🛡️ Mitigation

Users should monitor DNS resolver settings for unauthorised changes, remove unknown LaunchAgents, and delete any self‑signed certificates not explicitly approved. Running a reputable macOS antivirus solution (e.g., Malwarebytes, SentinelOne) will detect and block MaMi. Network administrators can block outbound connections to the known malicious IPs and domains.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.