Netskope Threat Labs

MacMa

ATP Sandbox Adv. HeuristicsAV

MacMa is a macOS backdoor with a large set of functionalities for controlling and exfiltrating files from compromised computers, observed in the wild since November 2021. It shares command and control infrastructure and unique libraries with MgBot and Nightdoor, which ties it to the Daggerfly threat actor.

First seen
November 2022
Last seen
October 2026
DazzleSpyMacma

27 techniques across 10 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

  • T1095Non-Application Layer Protocol
  • T1105Ingress Tool Transfer
  • T1571Non-Standard Port
  • T1573Encrypted Channel

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
Gen:Variant.Trojan.MAC.Macma.1
Gen:Variant.Trojan.MAC.Macma.2
Gen:Variant.Trojan.MAC.Macma.3
MacOS.Backdoor.Macma
MacOS.Trojan.DazzleSpy
MacOS.Trojan.Macma
Trojan.MAC.DazzleSpy.B
Trojan.MAC.Macma
Trojan.MAC.Macma.1
Trojan.MAC.Macma.3