Skip to content
safemode.space
All incidents
2016-09-26 (approximate)
cyber espionage
supply chain

APT28 Komplex macOS trojan delivered with a Russian space-programme decoy (2016)

Confidence in this reading:
moderate

What happened

In September 2016 Palo Alto Networks Unit 42 published an analysis of Komplex, a multi-stage OS X trojan it attributed to Sofacy, the group also tracked as APT28 and Fancy Bear. The sample's binder component drops a decoy document and executes a dropper, which installs persistence through a property list loaded at startup and launches the payload from a hidden path under /Users/Shared. The decoy is a Russian-language document on the projects of the Russian Federal Space Program for 2016-2025, and it is from that document, not from any named victim, that Unit 42 infers the target is likely associated with the aerospace industry. A prior campaign is reported to have delivered Komplex by exploiting a vulnerability in the MacKeeper application. In February 2017 Bitdefender published an analysis of the macOS build of Xagent, APT28's modular backdoor, and established that Komplex is its downloader and installer, linking the two through shared modules, matching C2 URL patterns and a common build path string. The macOS Xagent carries browser-password harvesting, screen capture, process monitoring and theft of iPhone backups stored on the compromised Mac.

ONE TECHNIQUE EDGE, AND THIS GLOSS SAID THERE WERE NONE FROM 2026-08-05 UNTIL 2026-08-22. The record carries EX-0010 Malicious Code at direct/high, whose own rationale records that it was "previously rejected only because SPARTA writes EX-0010 on the vehicle and this code ran on macOS laptops", which is the segment restriction decision 67 retires. The malware analysis is solid and the attribution is a named vendor's, but the entire space nexus is one decoy document: a Russian space-programme file that the analysts use to infer a likely aerospace-industry target. No victim is named, no space system is touched, and the behaviour, macOS enterprise espionage, has no counterpart in a spacecraft-scoped framework. Of the two techniques SPARTA's bibliography cites, RD-0004.02 Upload Exploit/Payload is defined on mission staging infrastructure and is not what happened. EX-0010 was rejected on the same segment reasoning and was recovered under decision 67. This gloss previously cited starlink-api-ddos-2022 and gonets-ground-crm-compromise-2022 as zero-edge precedent. Those two records still carry none; this one does, so the comparison no longer describes it. A second correction to the brief's framing: the September 2016 reporting SPARTA cites is about Komplex; the macOS Xagent it downloads was not published until February 2017, so the 'Xagent macOS trojan, 2016' description merges two disclosures. SCOPE UNDETERMINED, recorded 2026-08-23. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space-sector organisation is expressly not the test. What the sources establish is the malware end to end: a binder that saves a decoy document and runs a dropper, persistence through a launch agent that reloads a payload from a hidden path at every start, beaconing to command and control domains impersonating Apple services, and a later analysis linking the downloader to the macOS build of the group's modular backdoor. What no cited source establishes is who was attacked. Unit 42 says so twice in its own voice, "We do not have detailed targeting information regarding the Sofacy group's attack campaign delivering Komplex at this time" and "While detailed targeting information is not currently available", and its inference that the target is "likely associated with the aerospace industry" rests on the decoy document and on nothing else. That decoy is a file about the Russian Federal Space Program which the malware itself writes to the victim's machine, so it is an artefact of the lure rather than a system in the path. What was read therefore establishes that the victim environment was never described, not that no space system was in it, and those are different findings. A source naming the victim and the function of a compromised machine, or stating what the implant reached, would settle it: a mission operations, ground segment or spacecraft engineering host, or exfiltration of spacecraft material, would settle it one way; browser passwords and phone backups taken from a general-purpose Mac would settle it the other. Naming an aerospace employer alone would not settle it either way. The record stays published while the question is open, under decisions entry 189.

Attack vector

A multi-stage OS X trojan whose binder drops a decoy document on the Russian Federal Space Program and executes a dropper; a prior campaign is reported to have delivered it through a MacKeeper vulnerability.

Operational impact

None reported. No victim is named and no space system is described as reached.

Data compromised

None established. The macOS Xagent payload's capabilities (browser passwords, screenshots, iPhone backups) are described from the sample, not from an observed compromise.

Affected segments

supply_chain

Disclosed

2016-09-26

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • Unit 42 documents the Komplex binder dropping a decoy and executing a dropper, which installs persistence through a property list loaded at startup (com.apple.updates.plist, RunAtLoad true) and launches the payload from a hidden path under /Users/Shared; Bitdefender establishes that the payload is the macOS build of Xagent. Adversary-introduced executable logic ran on victim systems. Recovered per decision 67: previously rejected only because SPARTA writes EX-0010 on the vehicle and this code ran on macOS laptops. The record's HOLD stands on separate grounds: its only space nexus is the decoy document.

    https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • No trust relationship is ridden; no vendor route into a mission is described.

  • Pre-positioning packages in provider portals, scheduler queues or ground station file drops, formatted to mission protocols with CRC/MAC fields and timetags. An emailed OS X binder is not this.

  • Considered on the strength of the decoy's subject. Rejected: a decoy document reveals the adversary's targeting hypothesis, not what was collected. No source says space design material was sought or taken.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • Sofacy's 'Komplex' OS X Trojan
    Vendor threat intelligence

    Palo Alto Networks Unit 42 · Dani Creus, Tyler Halfpop, Robert Falcone · 2016-09-26

    Tier 2: Named vendor malware analysis with three named authors, the sample's stages described, the persistence mechanism given and the C2 domains listed.

  • New Xagent Mac Malware Linked with the APT28
    Vendor threat intelligence
    supporting

    Bitdefender · Bogdan Botezatu · 2017-02-14

    Tier 2: Named vendor malware analysis identifying the macOS Xagent payload and its link to the Komplex downloader through shared modules, C2 URL patterns and a shared build path.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.