MacMa
MITRE ATT&CK: S1016 View on attack.mitre.org
Aliases: OSX.CDDS, DazzleSpy, MacMa
- First seen
- 2021-11-01 00:00:00
- Malware type
- backdoor, spyware
- Family
- Malware family
- Operating systems
- macos
- Profile updated
- 2026-07-07 13:23:55
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:hk country_code:cn
Context
MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021. MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.
Detection coverage
- 292 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Code Signing (attack-pattern)
- Screen Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Launch Agent (attack-pattern)
- Data from Local System (attack-pattern)
- Remote Services (attack-pattern)
- Native API (attack-pattern)
- Audio Capture (attack-pattern)
- Keychain (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Process Discovery (attack-pattern)
- Timestomp (attack-pattern)
- Non-Standard Port (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Keylogging (attack-pattern)
- Clear Linux or Mac System Logs (attack-pattern)
- Unix Shell (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Gatekeeper Bypass (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Encrypted Channel (attack-pattern)
Used by threat actors
- Daggerfly (threat-actor)
Reports & references
- Broadcom/Symantec — Daggerfly Espionage Updated Toolset (report)
- MITRE ATT&CK — S1016 (report)
- objective-see.org — Blog 0X69 (report)
- ESET — Watering Hole Deploys New Macos Malware Dazzlespy Asia (report)