Dok

Aliases: Retefe

Malware type
trojan, dropper
Family
Malware family
Last IoC activity
2026-07-21 04:29:20
Profile updated
2026-07-07 14:09:34

Targeted industries: financial-services

Targeted regions: country_code:ch country_code:se country_code:uk country_code:de country_code:at

Context

Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Retefe_Auto (yara-rule)

Reports & references

  • govcert.admin.ch — The Retefe Saga (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Retefe (report)
  • blog.checkpoint.com — Osxdok Refuses Go Away Money (report)
  • blog.checkpoint.com — Osx Malware Catching Wants Read Https Traffic (report)
  • proofpoint.com — 2019 Return Retefe (report)

External references