FruitFly
MITRE ATT&CK: S0277 View on attack.mitre.org
Aliases: Quimitchin, FruitFly
- First seen
- 2017-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- macos
- Profile updated
- 2026-07-07 13:41:26
Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits
Context
FruitFly is a piece of spyware designed to target macOS systems, employing methods to capture screenshots and log keystrokes. It has been used to collect information primarily from organizations in the healthcare and education sectors.
Detection coverage
- 67 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Screen Capture (attack-pattern)
- Command Obfuscation (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Launch Agent (attack-pattern)
Reports & references
- objective-see.com — Blog 0X25 (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Fruitfly (report)
- documentcloud.org — 4346338 Phillip Durachinsky Indictment (report)
- arstechnica.com — Perverse Malware Infecting Hundreds Of Macs Remained Undetected For Years (report)
- objectivebythesea.com — Obts V3 Treed (report)
- virusbulletin.com — Vb2017 Paper Offensive Malware Analysis Dissecting Osxfruitflyb Custom Cc Server (report)
- blog.malwarebytes.com — New Mac Backdoor Using Antiquated Code (report)
- arstechnica.com — Newly Discovered Mac Malware May Have Circulated In The Wild For 2 Years (report)
- MITRE ATT&CK — S0277 (report)