X-Agent (OS X)

First seen
2016-07-01 00:00:00
Malware type
rat, spyware, backdoor
Family
Malware family
Profile updated
2026-07-07 14:31:20

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:us country_code:ua

Context

X-Agent (OS X) is part of a malware suite used by APT28, also known as Fancy Bear. It targets Apple macOS operating systems, designed to conduct espionage activities by providing a remote access tool (RAT) for data extraction and monitoring.

Reports & references

  • secureworks.com — Iron Twilight (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Xagent (report)
  • download.bitdefender.com — Bitdefender Whitepaper Apt Mac A4 En En Web (report)
  • researchcenter.paloaltonetworks.com — Unit42 Xagentosx Sofacys Xagent Macos Tool (report)
  • twitter.com — 845009226388918273 (report)

External references