Alpha Cyber

Sneaky “FruitFly” RAT Rat: Visualizing the Infrastructure Behind a Long-Running Threat

For years, the stealthy FruitFly remote access trojan (RAT) quietly operated beneath the radar, targeting macOS systems with an unusual blend of simplicity and persistence.

Alpha Cyber Research2 min readupdated 1 Apr 2026
FruitFly Rat

Sneaky “FruitFly” RAT Malware: Visualizing the Infrastructure Behind a Long Running Threat

For years, the stealthy FruitFly remote access trojan (RAT) quietly operated beneath the radar, targeting macOS systems with an unusual blend of simplicity and persistence. Although its codebase was not especially advanced, its longevity and the scale of its surveillance capabilities highlight a critical truth in cybersecurity: even modest malware can create massive impact when left undetected.

A Threat With a Human Story Behind It

The FruitFly RAT is linked to its creator, Phillip R. Durachinsky, a 28yearold at the time of his indictment. His campaign spanning schools, healthcare institutions, small businesses, and private individuals underscored just how broad the attack surface becomes when threat actors blend patience with targeted reconnaissance.

The malware’s purpose was chillingly human: watch, monitor, and silently collect. That capability, backed by patient infrastructure management, turned FruitFly into one of the more deeply invasive espionage tools in recent years.

What Makes FruitFly Notable?

Despite its relatively simple code structure, FruitFly stood out for:

FruitFly Virustotal

Long term operation without detection
Cross platform compatibility on older macOS systems
Surveillance centric functionality, including camera access and file collection
A manually controlled infrastructure supporting victim monitoring in real time

This combination of persistence, privacy invasion, and infrastructure based command and control is exactly why infrastructure visibility remains a cornerstone of modern cyber defense.

Mapping the FruitFly Infrastructure: Why Visibility Matters

FruitFly Rat Graph

Although the malware itself was small, its operational footprint was not. By reviewing publicly known data and indicators such as the SHA256 hash befa9bfe488244c64db096522b4fad73fc01ea8c4cd0323f1cbdee81ba008271 security teams can visualize how threat operators organize their command servers, manage victim communication, and evolve their campaigns over time.

Infrastructure mapping supports:

Identifying relationships between malware samples, domains, and IPs
Revealing attacker patterns such as preferred hosting providers or geographic regions
Highlighting weak links in an adversary’s operational chain
Enabling proactive threat hunting by recognizing repeating network behaviors

In FruitFly’s case, mapping revealed the methodical setup behind the surveillance: a small but persistent network structured to quietly maintain longterm access to compromised devices.

IOCS to Block

IndicatorTypeDescriptionAction
eidk.duckdns.orgDomainPotentially suspicious or malicious domainBlock
eidk.hopto.orgDomainPotentially suspicious or malicious domainBlock
eutq.hopto.orgDomainPotentially suspicious or malicious domainBlock
tmp1.hopto.orgDomainPotentially suspicious or malicious domainBlock
tmp2.hopto.orgDomainPotentially suspicious or malicious domainBlock

Why Organizations Should Pay Attention

FruitFly is a powerful example of how:

  • Outdated systems remain high value targets
  • Even simple RATs can operate for years undetected
  • Attackers rely on infrastructure discipline not just code complexity

As cyber threats evolve, the ability to visualize malicious infrastructure becomes critical for modern organizations. It turns scattered indicators into meaningful intelligence and gives defenders the strategic advantage needed to disrupt attacks before they escalate.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]