Dok
Aliases: Retefe
- Malware type
- trojan, dropper
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:29:20
- Profile updated
- 2026-07-07 14:09:34
Targeted industries: financial-services
Targeted regions: country_code:ch country_code:se country_code:uk country_code:de country_code:at
Context
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Retefe_Auto (yara-rule)
Reports & references
- govcert.admin.ch — The Retefe Saga (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Retefe (report)
- blog.checkpoint.com — Osxdok Refuses Go Away Money (report)
- blog.checkpoint.com — Osx Malware Catching Wants Read Https Traffic (report)
- proofpoint.com — 2019 Return Retefe (report)