MacProStorage:_2017Final:Bitdefender-Whitepaper-APT-Mac-A4-en_EN:Bitdefender-Whitepaper-APT-Mac-A4-en_EN.indd
ID: d920cb04-80f0-4eb7-8adf-ede07377610f
STIX ID: report--d920cb04-80f0-4eb7-8adf-ede07377610f
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2017-02-21
Last Modified Date: 2017-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender dissects an APT28 (Sofacy) Mac OS X backdoor (XAgent) delivered via the Komplex binder/dropper: the report details initialization, persistence, RC4+base64 HTTP GET/POST C2 communication, hardcoded C2 domains/IPs and a command set, and modular espionage functionality (keylogger, screenshots, remote shell, file exfiltration including iOS backups). The paper provides code excerpts, module descriptions, IOCs and mapping to other platform variants, highlighting a sophisticated nation-state-grade malware campaign targeting macOS.
