Digita Security

Cybersecurity solutions for the

  • modern
  • mobile
  • independent
  • innovative
  • enterprising

macOS workforce

6.15.2010 ( Version -3 )

HellRTS

Also Known As: OSX/Pinhead, OSX/HellRaiser

OSX/HellRTS is a Remote Access Trojan (RAT) targeting Mac OS X by posing as an innocent file. Once installed, the trojan has virtually complete control of the computer and can steal information, download additional files, and spy on the users. Variants were discovered as early as 2005 [1]. This was the first XProtect signature to be silently added as part of a Snow Leopard update, specifically to version 10.6.4 [2].

References:
  1. https://www.securemac.com/osx/trojan-horse-alert-hellraiser-aka-osxhellrts-d
  2. https://www.macstories.net/news/os-x-10-6-4-updates-anti-malware/

Sample Hashes (VT links):
797d7b60081368e50cb7d89c5d51c5d267a88a88
a8afa8e646bd6a02cfaa844735b94c50820bb9f5
0ba58f54b44b2ee8a1f149e1a686deeedebb79ba