#macOS

Malware/Tool

2019-09-20 • Mac Malware that Spoofs Trading App Steals User Information, Uploads it to Website

macOS is Apple’s desktop operating system and a target platform, not a malware family. North Korea-linked intrusion chains against cryptocurrency, Web3, gaming, and developer targets have delivered shell scripts, fake meeting installers, and Mach-O payloads through compromised Telegram contacts and ClickFix-style prompts. Reported implants include the Rust-based Gaslight stealer and backdoor, which collects browser data, command histories, keychain files, process details, and system profiles while using Telegram for encrypted command and control. Other campaigns used JavaScript-bearing Mach-O RATs and AppleScript-led execution followed by repeated HTTP POST signaling.

Tagged Reports

« Back