#macOSMalware
TraderTraitor used counterfeit Terraform tests to install FLATROOF, ROOFDECK backdoors on macOS devs—cloud access compromised early. #CloudSecurity #macOSMalware #DevSecOps #TraderTraitor thedailytechfeed.com/tradertraito...
September 21, 2026 at 1:56 PM
Alert: JINX-0164 targets crypto firms via LinkedIn, deploying custom macOS malware. Stay vigilant against social engineering attacks. #CyberSecurity #macOSMalware #LinkedInThreats #CryptoSecurity Link: thedailytechfeed.com/jinx-0164-us...
May 30, 2026 at 3:14 PM
What is old is new again, #atomicstealer being distributed via #clearfake campaign. Haven't seen that in a while!

Clearfake domain: cejecuu4[.]xyz
C2: 193.124.185[.]23

Payload staged in Dropbox

#macosmalware #infostealers #amos #fakebrowserupdates #fakechrome
August 6, 2024 at 7:08 AM
North Korean hackers are deploying NimDoor macOS malware via fake Zoom updates, targeting crypto firms. Stay vigilant! #CyberSecurity #NimDoor #macOSMalware #CryptoSecurity Link: thedailytechfeed.com/north-korean...
July 3, 2025 at 3:08 PM
🔍 Understanding macOS Malware is crucial for any professional today.

Check out my in-depth guide on analyzing PKG files to enhance your skills in macOS Malware Analysis: www.malwr4n6.com/post/macos-m...

#macos #malwareanalysis #macosmalware #apple #malware #guide
macOS Malware Analysis : PKG Files
There are very few resources on macOS Malware Analysis of native file types. I have often struggled to learn it in the beginning. Hence I decided to write a detailed article on PKG file analysis!
www.malwr4n6.com
March 7, 2025 at 10:43 AM
AmnesiaStealer is a game-changer for macOS threats. This new malware establishes live, interactive control over your browser sessions, enabling real-time identity impersonation. It's time to rethink how you protect your Mac.

https://www.tpp.blog/18sls7j

#cybersecurity #amnesiasteler #macosmalware
August 16, 2026 at 6:19 PM
AmnesiaStealer is busily harvesting macOS keychains, passwords, and browser cookies. So much for Apple devices being completely immune.

#macosmalware #justanothertue
August 14, 2026 at 11:33 AM
Beware of ClickLock, a new macOS malware identified by Group-IB. It doesn't use complex exploits, but rather psychological pressure tactics—like endless fake login prompts and system crashes—to trick you into revealing your…

https://www.tpp.blog/23hurnt

#technology #clicklock #macosmalware
July 17, 2026 at 7:17 AM
NimDoor: North Korean Hackers Deploy Sophisticated macOS Malware Targeting Web3 and Crypto Firms #cryptocurrencyattacks #MacOSMalware #malware
NimDoor: North Korean Hackers Deploy Sophisticated macOS Malware Targeting Web3 and Crypto Firms
  North Korean state-sponsored hackers have rolled out a new macOS malware strain dubbed NimDoor, designed to infiltrate Web3 and cryptocurrency organizations. According to a fresh analysis by SentinelOne researchers, the attackers leveraged uncommon methods and an innovative signal-based persistence mechanism never observed before. The attack chain starts with threat actors reaching out to potential victims through Telegram, persuading them to execute a bogus Zoom SDK update distributed via Calendly invitations and email—an approach reminiscent of tactics recently attributed to BlueNoroff by the managed security provider Huntress. SentinelOne’s report notes that the adversaries used a mix of C++ and Nim-compiled binaries (collectively referred to as NimDoor) on macOS—"a more unusual choice." One of these binaries, named 'installer,' handles the initial setup by preparing directories and configuration paths. It then deploys two additional components—'GoogIe LLC' and 'CoreKitAgent'—onto compromised systems. GoogIe LLC focuses on harvesting environment details and generating a hex-encoded configuration file, which is saved in a temporary directory. It also sets up a macOS LaunchAgent (com.google.update.plist) to ensure the malware runs automatically at login and retains authentication keys for future use. The most advanced piece of the toolkit is CoreKitAgent, the primary payload of NimDoor. This event-driven binary leverages macOS’s kqueue mechanism for asynchronous execution and implements a 10-state machine with a hardcoded transition table, enabling dynamic control depending on runtime conditions. A particularly distinctive characteristic is CoreKitAgent’s signal-based persistence, which relies on custom handlers for SIGINT and SIGTERM—signals typically used to terminate processes. "When triggered, CoreKitAgent catches these signals and writes the LaunchAgent for persistence, a copy of GoogIe LLC as the loader, and a copy of itself as the trojan, setting executable permissions on the latter two via the addExecutionPermissions_user95startup95mainZutils_u32 function," SentinelLABS explains. "This behavior ensures that any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions." Once active, CoreKitAgent decodes and executes a hex-encoded AppleScript that connects to command-and-control servers every 30 seconds, exfiltrates system information, and executes remote commands via osascript, effectively acting as a stealth backdoor. Alongside the main NimDoor infection, a parallel chain initiated by 'zoom_sdk_support.scpt' deploys 'trojan1_arm64', which establishes WebSocket Secure (WSS)-based communications with attacker infrastructure. It downloads two additional scripts—upl and tlgrm—to facilitate data theft. Notably, researchers discovered that the loader script contains over 10,000 blank lines to hinder detection. Upl focuses on extracting browser data, Keychain credentials, and shell history files (.bash_history and .zsh_history), transmitting the stolen information to dataupload[.]store via curl. Meanwhile, tlgrm targets Telegram data, including .tempkeyEncrypted files, likely to decrypt private messages exchanged on the platform. Overall, SentinelLABS describes NimDoor and its associated payloads as among the most complex macOS malware attributed to North Korean threat actors so far. The framework’s modular architecture and the use of novel persistence techniques underscore how DPRK operators are continuously refining their cross-platform attack capabilities to breach cryptocurrency ecosystems and steal sensitive information. SentinelLABS’ comprehensive report provides detailed indicators of compromise, including malicious domains, file paths, scripts, and binaries linked to these intrusions.  
dlvr.it
July 10, 2025 at 6:54 PM
New Infinity Stealer malware targets macOS by delivering Python payloads compiled with Nuitka, using fake ClickFix Cloudflare CAPTCHAs to steal browser credentials, Keychain data, crypto wallets, and dev secrets. #macOSMalware #InfoStealer
New Infinity Stealer malware grabs macOS data via ClickFix lures
A new info-stealing campaign called Infinity Stealer targets macOS by delivering a Python payload compiled into a native executable with the Nuitka compiler and lures users via a ClickFix fake Cloudflare CAPTCHA. The payload performs anti-analysis checks, harvests browser credentials, macOS Keychain entries, cryptocurrency wallets and plaintext developer secrets, and exfiltrates data to a C2 via HTTP while notifying operators via Telegram; users should never paste unknown commands into Terminal. #InfinityStealer #Nuitka
www.hendryadrian.com
March 28, 2026 at 7:00 PM
Infiniti Stealer targets macOS using a fake Cloudflare page to trick users into running a Bash dropper. It steals browser creds, Keychain data, wallets, and dev secrets, exfiltrating via HTTP and notifying via Telegram. #InfinitiStealer #MacOSMalware
Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka
Infiniti Stealer is a previously undocumented macOS infostealer delivered via a ClickFix social‑engineering scheme that tricks users into pasting a Terminal command to fetch a Bash dropper and ultimately runs a Nuitka‑compiled Python stealer. The malware decodes and executes staged payloads, removes quarantine flags, harvests browser credentials, Keychain entries, wallets, and...
www.hendryadrian.com
March 27, 2026 at 2:00 AM
March 25, 2026 at 4:01 PM
February 4, 2026 at 4:00 PM
December 30, 2025 at 5:30 PM
A new macOS malware uses fake error messages to confuse AI analysis tools, making detection difficult. It's an advanced tactic to evade security measures. #MacOSMalware
New macOS malware embeds fake errors to confuse AI analysis tools
A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable.
www.bleepingcomputer.com
June 26, 2026 at 10:05 AM