#JokerSpy

Malware/Tool

2023-06-16 • Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack

Its tooling includes Python backdoors, the SwiftBelt reconnaissance utility, and a Swift Mach-O stager called XCC that masquerades as Apple's XProtect malware-checking service and checks Full Disk Access and Screen Recording permissions. A suspected infection vector was a trojanized Java QR-code generator named QRLog, whose added QRCodeWriter.java file detected the host operating system, downloaded an appropriate payload, and opened a reverse shell. Other reporting on a Japanese cryptocurrency exchange indicates that the XCC stager downloaded a Python backdoor used to deploy SwiftBelt, while the exact delivery route and broader attribution remained uncertain.

Tagged Reports

« Back