Malware
Dok
aka Retefe
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe.
Dok, also known as Retefe, is a macOS malware family.
Background
Dok, also called Retefe, is the macOS edition of the Retefe banking trojan. It comes as a codesigned Mach-O dropper that is typically spread via malspam inside an app bundle packaged in a DMG disk image and disguised as a document. The dropper's main job is to install a Tor client along with a rogue CA certificate and a proxy pac URL so that traffic to targeted sites is routed through the attackers' Tor node, amounting to a MITM attack against selected web traffic. It additionally drops a custom hosts file that blocks access to Apple and VirusTotal. The macOS variant mirrors the modus operandi, many of the TTPs, and the infrastructure of its Windows counterpart.
Source: Malpedia (Fraunhofer FKIE).