#JokerSpy
Malware/Tool
2023-06-16 • Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack
Its tooling includes Python backdoors, the SwiftBelt reconnaissance utility, and a Swift Mach-O stager called XCC that masquerades as Apple's XProtect malware-checking service and checks Full Disk Access and Screen Recording permissions. A suspected infection vector was a trojanized Java QR-code generator named QRLog, whose added QRCodeWriter.java file detected the host operating system, downloaded an appropriate payload, and opened a reverse shell. Other reporting on a Japanese cryptocurrency exchange indicates that the XCC stager downloaded a Python backdoor used to deploy SwiftBelt, while the exact delivery route and broader attribution remained uncertain.
-
9
Tagged Reports
-
7
Unique Authors
-
301
Active Days