logo

Forced to Adapt: XSLCmd Backdoor Now on OS X | FireEye Blog

ID: 6bd62a0a-a3e1-40b3-9281-be1121acdc35

STIX ID: report--6bd62a0a-a3e1-40b3-9281-be1121acdc35

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2014-10-11

Last Modified Date: 2014-10-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** FireEye Labs reports discovery and analysis of an OS X variant of the XSLCmd backdoor used by the APT actor tracked as GREF; the analysis covers installation/persistence (LaunchAgents, plist, privileged copy behavior), capabilities (reverse shell, file operations, keylogging, screen capture), pseudo-HTTP C2 protocol and configuration (MServer/BServer, FakeDomain, MServer IP 61.128.110.38 and FakeDomain www.appleupdate.biz), and supporting threat intelligence on GREF's historical targeting, tooling, and domain registration clusters.