Executive Summary
FruitFly is an advanced macOS spyware that persists via launch agents, harvests credentials, keystrokes, screenshots, and exfiltrates data over encrypted channels. The malware’s stealthy behavior can enable attackers to gain elevated access and expand lateral movements within networks.
Enhanced Description
FruitFly is a macOS‑targeted spyware family first reported by the research group ObjSee in 2017. Its primary objective is to covertly gather sensitive user information and exfiltrate it from infected systems. The malware injects itself into legitimate system processes or installs as a launch agent, ensuring persistence across reboots while remaining difficult for users to detect. Once active, FruitFly enumerates the file system for documents, captures screenshots, logs keystrokes, and harvests stored passwords from the Keychain. Network activity is typically directed to hardened command‑and‑control (C2) servers over HTTPS or custom protocols, allowing adversaries to orchestrate further compromise on a larger scale. Impact extends beyond personal data theft: by compromising credential stores and system logs, FruitFly can provide attackers with administrative access, enabling lateral movement inside corporate networks. Its modular architecture and ability to obfuscate traffic make it a potent threat for both individual and enterprise macOS environments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information available is based on a single public reference from 2017, with no recent sample analysis or detailed technical disassembly. While the core capabilities are inferred accurately on the basis of known macOS spyware tactics, specific persistence mechanisms, command‑and‑control infrastructure, and potential anti‑analysis techniques remain uncertain. Gaps exist in current indicators (file names, hash values), the exact variant variants used today, and any attribution to threat actors.
FruitFly is designed to spy on mac users (Citation: objsee mac malware 2017).