Our team recently published 2026 #macOS malware predictions: supply-chain + AI/workflow (MCP) abuse, signed/notarized stealth & multi-stage loaders, Macs as proxy infrastructure, and “upmarket” infostealers.
Give it a read! 👇
https://t.co/GE2r8klkqw
1/ New #macOS bash dropper - 0 hits on VT. Shared by @malwrhunterteam.
Self-deletes on launch. Delivers a binary from weekly-up[.]online while pushing a fake Zoom, Teams, or SystemApp as cover.
Might be related to Contagious Interview, however no strong confirmation yet. 🧵
@blackbigswan Thanks for sharing this info, it's very valuable!
Yes, we are not 100% sure it is DPRK-related as well, so not making any statements yet .. just that the approach is similar.
5/ While the decoy app loads, winapp_fork_bins() fires two curl processes in the background, pulling the real payload from weekly-up[.]online/2?type=sh into TMPDIR under a randomly-generated name.
The loop runs indefinitely, and filename is runtime-random.
1/ Looks like #DigitStealer is still hard to detect on VT. @malwrhunterteam shared a file with us which led to Stage-1 compiled AppleScript. With multiple parallel scripts to execute, it remains a threat to #macOS users.
More info below 👇
1/ New #macOS (crossplatform) sample: a full-featured remote access trojan masquerading as MicrosoftSystem64 and using #huggingface legitimate infrastructure for its C2 activities. JavaScript payload + RAT inside a Mach-O binary. Findings below 👇