LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0274: Calisto

Calisto is a macOS Trojan that opens a backdoor on the compromised machine. Calisto is believed to have first been developed in 2016. [1] [2]

EnterpriseS0274MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Calisto is a macOS Trojan described by ATT&CK as opening a backdoor on a compromised machine. Its ATT&CK relationships make it material beyond “Mac malware”: the mapped behaviors include local data collection, browser and network discovery, Keychain credential access, local account creation, Launch Agent persistence, launchctl execution, hiding/deleting files, staging and archiving data, and tool transfer. For leaders, this is a reminder that macOS endpoints need the same identity, credential, persistence, and data-loss visibility expected on other enterprise platforms.

Executive priority

Prioritize validation of macOS security coverage where executives, developers, administrators, or privileged users operate from Macs. The business risk is not just device infection; the mapped behaviors touch credential exposure, persistent access, local data theft preparation, and account manipulation. Ask whether SOC, IR, and audit teams can prove visibility into macOS persistence, Keychain-related access, local account changes, suspicious file staging, and outbound tool transfer rather than relying on Windows-centric controls.

Technical view

ATT&CK provides no official detection text for Calisto, so defenders should validate coverage through the related techniques. On macOS, focus on Launch Agent and launchctl activity, creation or modification of local accounts, attempts to access Keychain material, browser information discovery, local file enumeration and staging, archive utility usage, hidden files/directories, file deletion, and inbound file/tool transfer. Detection engineering should correlate these behaviors rather than depend on a single malware name, especially because masquerading as legitimate resource names or locations is included in the mapped behavior set.

Likely telemetry

  • macOS endpoint process execution events, including launchctl and archive utilities
  • File system events for hidden files/directories, suspicious staging locations, file deletion, and newly written tools
  • Launch Agent plist creation or modification under macOS LaunchAgents paths
  • Local account creation and account/permission change records
  • Keychain access-related security events where available

Detection direction

  • Build behavior-based detections around the related ATT&CK techniques rather than Calisto-specific naming alone.
  • Correlate Launch Agent persistence with launchctl execution, suspicious file paths, hidden files, or recently downloaded payloads.
  • Tune for legitimate administrative software that uses launchctl, compression utilities, or account management commands to reduce false positives.
  • Review whether macOS Keychain and browser-data access are visible enough for investigation; these are common blind spots compared with process and network logs.
  • Look for sequences: discovery, collection from local system, staging, archive creation, deletion/cleanup, and outbound transfer.

Mitigation priorities

  • Ensure macOS endpoints are included in managed detection, EDR, logging, and incident response playbooks.
  • Harden and monitor Launch Agents and launchctl usage, especially for nonstandard plist locations, unusual users, or suspicious executable paths.
  • Apply least privilege and review local administrator rights to reduce account manipulation and local account persistence risk.
  • Protect credential stores by limiting unnecessary access to Keychain data and investigating unexpected access patterns.
  • Control and monitor download/execution of untrusted tools and files on macOS systems.
Additional notes and limits

The ATT&CK object identifies Calisto as a macOS backdoor Trojan believed to have first been developed in 2016 and provides relationships to multiple techniques spanning discovery, collection, credential access, persistence, execution, command and control, and stealth. The object itself has no ATT&CK tactics listed and no official detection guidance, so defensive value comes from validating telemetry and controls against the mapped techniques.

This take is limited to the supplied ATT&CK fields, external references, and relationships. It does not assert current activity, attribution, victim exposure, or guaranteed detection. Local environment evidence is required to determine whether Calisto-like behaviors are visible, suspicious, or already controlled in a given organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Calisto

Calisto is a macOS Trojan that opens a backdoor on the compromised machine. Calisto is believed to have first been developed in 2016. [1] [2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1543.001Launch AgentSub-technique

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.[1]

EnterpriseT1217Browser Information Discovery

Calisto collects information on bookmarks from Google Chrome.[1]

EnterpriseT1016System Network Configuration Discovery

Calisto runs the ifconfig command to obtain the IP address from the victim’s machine.[1]

EnterpriseT1105Ingress Tool Transfer

Calisto has the capability to upload and download files to the victim's machine.[2]

EnterpriseT1056.002GUI Input CaptureSub-technique

Calisto presents an input prompt asking for the user's login and password.[2]

EnterpriseT1005Data from Local System

Calisto can collect data from user directories.[1]

EnterpriseT1070.004File DeletionSub-technique

Calisto has the capability to use rm -rf to remove folders and files from the victim's machine.[1]

EnterpriseT1569.001LaunchctlSub-technique

Calisto uses launchctl to enable screen sharing on the victim’s machine.[1]

EnterpriseT1560.001Archive via UtilitySub-technique

Calisto uses the zip -r command to compress the data collected on the local system.[1][2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.[1]

EnterpriseT1555.001KeychainSub-technique

Calisto collects Keychain storage data and copies those passwords/tokens to a file.[1][2]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.[1][2]

EnterpriseT1074.001Local Data StagingSub-technique

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.[1][2]

EnterpriseT1098Account Manipulation

Calisto adds permissions and remote logins to all users.[2]

EnterpriseT1136.001Local AccountSub-technique

Calisto has the capability to add its own account to the victim's machine.[2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
0a59c4aa836cc06d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle0a59c4aa836c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  2. [2]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  3. [3]
    Calisto

    (Citation: Securelist Calisto July 2018) (Citation: Symantec Calisto July 2018)

  4. [4]
    Calisto

    (Citation: Securelist Calisto July 2018) (Citation: Symantec Calisto July 2018)

  5. [5]
    Calisto

    (Citation: Securelist Calisto July 2018) (Citation: Symantec Calisto July 2018)

  6. [6]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  7. [7]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  8. [8]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  9. [9]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  10. [10]
    mitre-attackS0274
    Open source URL
  11. [11]
    mitre-attackS0274
    Open source URL
  12. [12]
    mitre-attackS0274
    Open source URL
  13. [13]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  14. [14]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  15. [15]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  16. [16]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  17. [17]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  18. [18]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  19. [19]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  20. [20]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  21. [21]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  22. [22]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  23. [23]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  24. [24]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  25. [25]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  26. [26]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  27. [27]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  28. [28]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  29. [29]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  30. [30]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  31. [31]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  32. [32]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  33. [33]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  34. [34]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  35. [35]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  36. [36]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  37. [37]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  38. [38]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  39. [39]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  40. [40]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  41. [41]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  42. [42]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  43. [43]
    Securelist Calisto July 2018

    Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018.

    Open source URL
  44. [44]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  45. [45]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
  46. [46]
    Symantec Calisto July 2018

    Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.