037. The Easiest Way to Detect a macOS Stealer

Hello everyone! What do you know about macOS stealers? Looks like one can buy it on underground resources. And yes, we're seeing it in-the-wild more and more often!


But we are interested in detection opportunities, of course! Let's look at a report published by Unit42. There's an overview of three stealers: Atomic Stealer, Poseidon Stealer and Cthulhu Stealer. If we look through the report, we can see a very distinct feature: all of them abuse AppleScript to obtain the victims' password!

So, what to look for? Look for osascript executions with display dialog and password in the command line! That's it! That easy!

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

001. The Zeltser Challenge

012. They Want to Know Everything About Your System!