logo

TrendLabs Security Intelligence BlogOSX Malware Linked to Operation Emmental Hijacks User Network Traffic - TrendLabs Security Intelligence Blog

ID: 1c960a3c-783c-4c76-ab75-c71ae38fcfb9

STIX ID: report--1c960a3c-783c-4c76-ab75-c71ae38fcfb9

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2017-07-11

Last Modified Date: 2017-07-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Trend Micro analysis describes OSX_DOK.C, a macOS banking trojan tied to Operation Emmental that arrives via phishing (malicious .zip/.docx), installs a fake App Store/update UI to capture credentials, abuses developer-signed certificates to install a root certificate and uses local proxies (127.0.0.1:5555 and 5588) plus Tor to perform selective MitM against Swiss banking websites; the report includes infection flow, hardcoded target domains, IOC details (proxy PAC URLs, bundle path, ports) and mitigation advice.