Skip to content

Phexia

Phexia is a modular macOS-focused infostealer and remote-access malware family.

Phexia

Family profile

Phexia is a modular macOS-focused infostealer and remote-access malware family. It contains information-stealing and reverse-shell functionality and has been characterized as a resident bot designed to support additional modules. Phexia establishes user-level persistence through a LaunchAgent that executes an encoded AppleScript payload. It uses dead-drop resolution through Telegram profiles, Steam profiles, and blockchain smart contracts to retrieve or rotate command-and-control infrastructure, enabling operators to change backend infrastructure without rebuilding the malware. Phexia has been distributed through malicious copy-and-paste lures that cause victims to execute shell and AppleScript commands. It has also been associated with abuse of blockchain infrastructure for infostealer distribution. Phexia emerged in the macOS stealer ecosystem alongside families such as Atomic Stealer and MacSync Stealer.

Capabilities

  • Credential Theft
  • Persistence
  • Post Exploitation

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

Phexia in ATT&CK

14 distinct techniques