Phexia
Phexia is a modular macOS-focused infostealer and remote-access malware family.
Phexia
Family profile
Phexia is a modular macOS-focused infostealer and remote-access malware family. It contains information-stealing and reverse-shell functionality and has been characterized as a resident bot designed to support additional modules. Phexia establishes user-level persistence through a LaunchAgent that executes an encoded AppleScript payload. It uses dead-drop resolution through Telegram profiles, Steam profiles, and blockchain smart contracts to retrieve or rotate command-and-control infrastructure, enabling operators to change backend infrastructure without rebuilding the malware. Phexia has been distributed through malicious copy-and-paste lures that cause victims to execute shell and AppleScript commands. It has also been associated with abuse of blockchain infrastructure for infostealer distribution. Phexia emerged in the macOS stealer ecosystem alongside families such as Atomic Stealer and MacSync Stealer.
Capabilities
- Credential Theft
- Persistence
- Post Exploitation
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
MITRE ATT&CK