Proton
MITRE ATT&CK: S0279 View on attack.mitre.org
Aliases: Proton
- First seen
- 2017-03-01 00:00:00
- Malware type
- backdoor, credential-stealer, spyware
- Family
- Malware family
- Operating systems
- macos
- Related IoCs
- 97 (83 malicious)
- Last IoC activity
- 2026-09-02 02:26:30
- Profile updated
- 2026-07-07 13:41:23
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Proton is a macOS backdoor focusing on data theft and credential access.
Recent IoC activity
83 malicious indicators in Maltiverse are attributed to Proton (S0279). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 185.107.56.235 | 2026-09-03 | 2 |
| IP address | 62.169.136.2 | 2026-09-03 | 2 |
| IP address | 149.22.95.193 | 2026-09-03 | 2 |
| IP address | 149.88.97.122 | 2026-09-03 | 2 |
| IP address | 89.187.171.225 | 2026-09-02 | 2 |
| IP address | 103.219.169.99 | 2026-09-02 | 4 |
| IP address | 195.181.162.163 | 2026-09-02 | 2 |
| IP address | 151.243.141.161 | 2026-09-02 | 2 |
| IP address | 89.187.185.161 | 2026-09-02 | 3 |
| IP address | 185.165.240.80 | 2026-09-02 | 2 |
| IP address | 149.22.82.55 | 2026-09-02 | 2 |
| IP address | 146.70.98.98 | 2026-09-02 | 2 |
| IP address | 37.19.200.17 | 2026-09-02 | 3 |
| IP address | 188.241.177.226 | 2026-09-02 | 2 |
| IP address | 37.19.199.139 | 2026-09-02 | 2 |
| IP address | 156.146.51.129 | 2026-09-02 | 2 |
| IP address | 138.199.50.98 | 2026-09-02 | 2 |
| IP address | 45.14.71.5 | 2026-09-02 | 2 |
| IP address | 89.39.106.82 | 2026-09-02 | 3 |
| IP address | 37.19.200.1 | 2026-09-02 | 2 |
Detection coverage
- 231 Sigma rules
Malware & tools used
- GUI Input Capture (attack-pattern)
- Launch Agent (attack-pattern)
- File Deletion (attack-pattern)
- VNC (attack-pattern)
- Sudo and Sudo Caching (attack-pattern)
- Keychain (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Clear Linux or Mac System Logs (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Keylogging (attack-pattern)
- Password Managers (attack-pattern)
- Screen Capture (attack-pattern)
- Archive Collected Data (attack-pattern)
- Unix Shell (attack-pattern)
Reports & references
- objective-see.com — Blog 0X25 (report)
- ransomlook.io — Proton (report)
- MITRE ATT&CK — S0279 (report)