Forced to Adapt: XSLCmd Backdoor Now on OS X | FireEye Blog
ID: 6bd62a0a-a3e1-40b3-9281-be1121acdc35
STIX ID: report--6bd62a0a-a3e1-40b3-9281-be1121acdc35
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2014-10-11
Last Modified Date: 2014-10-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** FireEye Labs reports discovery and analysis of an OS X variant of the XSLCmd backdoor used by the APT actor tracked as GREF; the analysis covers installation/persistence (LaunchAgents, plist, privileged copy behavior), capabilities (reverse shell, file operations, keylogging, screen capture), pseudo-HTTP C2 protocol and configuration (MServer/BServer, FakeDomain, MServer IP 61.128.110.38 and FakeDomain www.appleupdate.biz), and supporting threat intelligence on GREF's historical targeting, tooling, and domain registration clusters.
