Sofacy’s ‘Komplex’ OS X Trojan - Palo Alto Networks BlogPalo Alto Networks Blog
ID: 06d4ad9b-03e0-468d-bef1-e3e5f72003d9
STIX ID: report--06d4ad9b-03e0-468d-bef1-e3e5f72003d9
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2016-09-29
Last Modified Date: 2016-09-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 details 'Komplex', an OS X Trojan attributed to Sofacy (APT28) that uses a binder to drop a Mach-O dropper and payload, establishes persistence via a LaunchAgent plist and start script, communicates with encrypted C2 servers using an 11-byte XOR scheme, and contains IOCs (hashes and C2 domains) with links to a MacKeeper-based exploit and overlaps with Sofacy's Carberp tooling.
