Description
Dok is a macOS trojan that spread through phishing emails in 2018, primarily targeting users in Germany. It hijacked network traffic by changing system proxy settings, installed a root certificate to intercept encrypted connections, and stole browsing and credential data from infected machines.
Stats
- First seen
- April 2022
- Last seen
- September 2026
Also known as
Retefe
MITRE ATT&CK techniques
11 techniques across 9 tactics.
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Retefe |
| Script-JS.Trojan.Retefe |
| Trojan.MAC.Dok.A |
| Win32.Trojan.Retefe |

