MacMa
S1016 · macOS
MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021. MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.
ATT&CK S1016
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0