2026-08-23NOTABLEDead-drop C2 moved from novelty to routine, and the control is an egress baseline rather than a blocklist
Phexia
malware · malware:phexia single-source
macOS remote-access tool and stealer delivered through malicious copy-and-paste lures, resolving its command-and-control address from a public Polygon blockchain smart contract with Telegram and Steam profiles as redundant dead drops, and persisting through a launch agent (Red Canary, 2026-08-20).
Coverage
2
1 about it · 1 mention · first 2026-07-14 → last 2026-08-23
Latest activity
2026-08-23
Dead-drop C2 moved from novelty to routine, and the control is an egress baseline rather than a blocklist
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, telco · regions: europe
Sources cited
3
3 hosts
Action items (1)
Do-now tasks recorded on the entries about Phexia, newest first. Check the date before acting on an older one.
- Establish which users, systems and applications in your estate legitimately make HTTPS calls to public blockchain RPC endpoints (for most public-sector estates the honest answer is none) and alert on anything outside that set; chainlist.org enumerates the widely-used endpoints adversaries prefer.2026-08-23Dead-drop C2 moved from novelty to routine, and the…
Defender insights
What each entry about Phexia tells a defender to do, newest first.
Triage
Story timeline
Every entry that names Phexia, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-23Dead-drop command-and-control went commodity: three of four new entrants on Red Canary's monthly list resolve their C2 from a dead drop, two of them from a public blockchain, and the fourth is a GUI for Entra ID device-code phishing
- 2026-07-14CrashStealer, a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionUser Execution: Malicious Copy and Paste
- PersistenceCreate or Modify System Process: Launch Agent · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationCreate or Modify System Process: Launch Agent
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Modify Authentication Process: Multi-Factor Authentication
- Command and ControlWeb Service: Dead Drop Resolver
Execution TA0002
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Persistence TA0003
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Privilege Escalation TA0004
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Command and Control TA0011
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Entries about Phexia (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Apple macOS×1
- CastleRAT×1
- CrashStealer×1
- EtherRAT×1
- GraphSpy×1
- MacSync×1
- Microsoft 365×1
- Microsoft Entra ID×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- jamf.com1 (33%)
- redcanary.com1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/
- jamf.comJamf Threat Labshttps://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/
- redcanary.comRed Canaryhttps://redcanary.com/blog/threat-intelligence/intelligence-insights-august-2026/