LightSpy Malware Variant Targeting macOS | Huntress
ID: 85a91082-f381-57bf-8a91-3441ce2fe5e7
STIX ID: report--85a91082-f381-57bf-8a91-3441ce2fe5e7
Feed Name: Huntress Blog
Huntress analyzed a VirusTotal sample of the LightSpy framework and determined it is a macOS implant (x86_64) rather than iOS; the report details a three-stage architecture (dropper, implant dylib, plugins), plugin capabilities (audio recording, camera, screen recording, file and keychain access, remote shell, etc.), encryption/decryption and C2 mechanisms (WebSockets, macmanifest.json), IOCs (SHA1/SHA256 hashes, filenames) and infrastructure (primary C2 103.27.109.217), and provides YARA/Sigma detection rules and mitigations while noting limited evidence of a broader campaign and prior associations with APT41.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
