CISOOnline

New macOS malware turns stolen browsers into attacker-controlled sessions

The loader takes a number of steps to make the payload harder to notice, Jamf said. It extracts the binary into “/tmp,” gives it a hidden Apple-looking filename, removes the macOS quarantine attribute, applies an ad-hoc code signature and launches it silently before deleting the executable.

Password-protecting the ZIP is likely an attempt to complicate automated inspection, the researchers noted.

The Rust-based universal Mach-O finally deployed was analyzed to be built for both Intel and Apple silicon Macs. Jamf said that it can collect the macOS login password through a native-looking prompt, as well as target the Keychain, browser data, Apple Notes, Telegram session information and files.



Source link