logo

LightSpy Malware Variant Targeting macOS | Huntress

ID: 85a91082-f381-57bf-8a91-3441ce2fe5e7

STIX ID: report--85a91082-f381-57bf-8a91-3441ce2fe5e7

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2024-04-29

Date Updated: 2026-04-28

...
...

Huntress analyzed a VirusTotal sample of the LightSpy framework and determined it is a macOS implant (x86_64) rather than iOS; the report details a three-stage architecture (dropper, implant dylib, plugins), plugin capabilities (audio recording, camera, screen recording, file and keychain access, remote shell, etc.), encryption/decryption and C2 mechanisms (WebSockets, macmanifest.json), IOCs (SHA1/SHA256 hashes, filenames) and infrastructure (primary C2 103.27.109.217), and provides YARA/Sigma detection rules and mitigations while noting limited evidence of a broader campaign and prior associations with APT41.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.