Netskope Threat Labs

Dok

ATP Sandbox Adv. HeuristicsAV

Dok is a macOS trojan that spread through phishing emails in 2018, primarily targeting users in Germany. It hijacked network traffic by changing system proxy settings, installed a root certificate to intercept encrypted connections, and stole browsing and credential data from infected machines.

First seen
April 2022
Last seen
September 2026
Retefe

11 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

TA0005 Stealth

TA0006 Credential Access

  • T1557Adversary-in-the-Middle

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol
    • T1048.003Exfiltration Over Unencrypted Non-C2 Protocol

TA0112 Defense Impairment

  • T1222File and Directory Permissions Modification
  • T1553Subvert Trust Controls
Alert Name
ByteCode-MSIL.Trojan.Retefe
Script-JS.Trojan.Retefe
Trojan.MAC.Dok.A
Win32.Trojan.Retefe