037. The Easiest Way to Detect a macOS Stealer
Hello everyone! What do you know about macOS stealers? Looks like one can buy it on underground resources. And yes, we're seeing it in-the-wild more and more often!
But we are interested in detection opportunities, of course! Let's look at a report published by Unit42. There's an overview of three stealers: Atomic Stealer, Poseidon Stealer and Cthulhu Stealer. If we look through the report, we can see a very distinct feature: all of them abuse AppleScript to obtain the victims' password!
So, what to look for? Look for osascript executions with display dialog and password in the command line! That's it! That easy!
See you tomorrow!
Comments
Post a Comment