Digita Security

Cybersecurity solutions for the

  • modern
  • mobile
  • independent
  • innovative
  • enterprising

macOS workforce

5.7.2017 ( Version 2091 )

XProtect_OSX_Proton_B


OSX/Proton is a persistent Backdoor and Remote Access Trojan (RAT) that exfiltrates user data including passwords and browsing information [1]. A new variant was discovered in a compromised Handbrake installer in 2017 [2].

References:
  1. https://www.cybersixgill.com/proton-a-new-mac-os-rat/
  2. https://objective-see.com/blog/blog_0x1F.html

Sample Hashes (VT links):
51192679c33d2095e5c376a076f1bcd3c627d4fc47506b3dc3c274ee10aeb126