Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Keydnap

Keydnap

TLP:CLEAR
Family

Also known as: OSX/Keydnap

AI Analysis

· 2 days ago

Executive Summary

Keydnap is a macOS Trojan that stealthily harvests Keychain credentials and establishes persistent backdoor access through launch agents or login items. The exfiltrated data is sent to a remote C2 server, enabling attackers to deploy ransomware later if desired. Security teams should block outbound connections to known malicious domains, implement application whitelisting, and monitor for anomalous launch agent registrations.

Enhanced Description

Keydnap, also seen as OSX/Keydnap within the macOS threat landscape, is a credential‑stealing Trojan that targets the macOS Keychain. Once installed on a victim’s machine, Keydnap enumerates all keychain items—including passwords for email, web services, VPNs, and other secure storage—and compiles them into an encrypted payload for exfiltration. In addition to this theft phase, the malware establishes a long‑term persistence mechanism by creating a launch agent or login item that ensures it re‑installs itself after system restarts or user logouts. During execution Keydnap communicates with a command‑and‑control (C2) server over an outbound HTTPS channel. The C2 interface allows the adversary to issue remote commands, initiate additional credential harvests, and receive collected data in near real‑time. While the core functionality is focussed on keychain access, some variants have shown rudimentary ransomware capabilities—in particular, they can encrypt the victim’s Documents directory if a ransom is demanded. Because Keydnap operates entirely within user space and leverages legitimate macOS APIs for Keychain access, it evades many signature‑based defenses. The malware’s persistence via login items also makes traditional host‑based tools that only watch for executable drops ineffective unless coupled with user‑space process monitoring.

Key Capabilities

  • Steals all items from macOS Keychain
  • Exfiltrates harvested credentials over HTTPS to a command‑and‑control server
  • Creates persistent persistence via login items or launch agents
  • Supports remote command execution (e.g., trigger additional data theft, ransomware)
  • Can encrypt victim files as part of ransomware payload

ATT&CK Techniques

T1555
T1547.009
T1003
T1106

Recommended Actions

  • Deploy application whitelisting to block unknown macOS binaries from execution
  • Regularly audit and remove unauthorized launch agents or login items
  • Block outbound HTTPS traffic to known malicious domains or IP addresses used by Keydnap C2
  • Enable host–based intrusion detection sensors that flag suspicious keychain API usage
  • Educate users about phishing and the risks of installing untrusted applications
  • Maintain up‑to‑date anti‑virus signatures targeting known variants

Suggested Tags

macos
credential-stealer
keychain-access
persistence
backdoor
t1089
ransomware

Confidence Assessment

The available data provides a clear picture of Keydnap’s core credential‑stealing function and persistence strategy, but lacks detailed technical specifications such as exact API calls, encryption algorithms, or full variant taxonomy. Further samples would improve confidence in the complete attack chain, including ransomware components.

Description

This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor (Citation: OSX Keydnap malware).

Details

Type
Malware
Platforms
Macos
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.