Description
MacMa is a macOS backdoor with a large set of functionalities for controlling and exfiltrating files from compromised computers, observed in the wild since November 2021. It shares command and control infrastructure and unique libraries with MgBot and Nightdoor, which ties it to the Daggerfly threat actor.
Stats
- First seen
- November 2022
- Last seen
- October 2026
Also known as
DazzleSpyMacma
MITRE ATT&CK techniques
27 techniques across 10 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Trojan.MAC.Macma.1 |
| Gen:Variant.Trojan.MAC.Macma.2 |
| Gen:Variant.Trojan.MAC.Macma.3 |
| MacOS.Backdoor.Macma |
| MacOS.Trojan.DazzleSpy |
| MacOS.Trojan.Macma |
| Trojan.MAC.DazzleSpy.B |
| Trojan.MAC.Macma |
| Trojan.MAC.Macma.1 |
| Trojan.MAC.Macma.3 |