logo

Sofacy’s ‘Komplex’ OS X Trojan - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 06d4ad9b-03e0-468d-bef1-e3e5f72003d9

STIX ID: report--06d4ad9b-03e0-468d-bef1-e3e5f72003d9

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2016-09-29

Last Modified Date: 2016-09-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 details 'Komplex', an OS X Trojan attributed to Sofacy (APT28) that uses a binder to drop a Mach-O dropper and payload, establishes persistence via a LaunchAgent plist and start script, communicates with encrypted C2 servers using an 11-byte XOR scheme, and contains IOCs (hashes and C2 domains) with links to a MacKeeper-based exploit and overlaps with Sofacy's Carberp tooling.