Our Valentine's Day gift ๐
https://t.co/qjS1qRfbjR
Announcing Objective by the Sea (#OBTS) v9.0:
๐ฉ๐ปโ๐ผ Train: Nov 15-17
๐ฉ๐ปโ๐ซ Talks: Nov 18-20
๐ Maui, Hawaii, 2026
CFP (talks & trainings) and tickets are now officially open! Hope to see you by the sea ๐๏ธ
Special ๐๐ฝ to @andyrozen!!
One of the most time consuming parts of macOS research is identifying what you're looking at - AMOS, NovaStealer, DigitStealer, MacSync, or maybe Shlayer or Adload.
You can now pull in this Malware Research skill to help you classify malware quickly.
https://t.co/rPFZGnGuwD
Also, have posted a sample of PamStealer to our free/public Mac Malware repo! ๐๐
PamStealer:
https://t.co/uj0wVy0kiO (pw: infect3d)
#SharingIsCaring
Jamf's Thijs Xhaflaire analyses PamStealer, a Rust-based macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection. https://t.co/Q6TdzGN1gY
Meet CrashStealer. This one takes delivery more seriously than most, a signed and Apple-notarized dropper that's pulling its second stage payload down through GitHub.
The payload is a native C++ stealer with client-side AES-GCM encryption and layered anti-analysis.
Check out our writeup for additional details and indicators of compromise.
https://t.co/3IhuEmrsZj
#infostealer #malware #macos #threatresearch
Here's a cool uncommon technique seen in a dylib (written in beautiful Swift) for an App that had its signature revoked. Grabbing a config from the https://t.co/aIfm81wntX.metadata:kMDItemFinderComment xattr of an app bundle using the getxattr() func. cool!
Stoked to be presenting at the next "Berlin MacAdmins Meetup" ๐คฉ๐ฉ๐ช If you're around the Berlin area, join us!
โน๏ธTuesday, July 28th 7:00 - 10:00 PM
For more details & registration: https://t.co/kA0bYBSpiU
Mahalo to @JamfSoftware for sponsoring the event!๐๐ฝ
1/ New #macOS (crossplatform) sample: a full-featured remote access trojan masquerading as MicrosoftSystem64 and using #huggingface legitimate infrastructure for its C2 activities. JavaScript payload + RAT inside a Mach-O binary. Findings below ๐
The latest macOS ClickFix variant invisibly mounts DMG images in the background to execute a macOS infostealer and hijack cryptocurrency wallet info. Details at https://t.co/8Bg5ojzg26
Lineup for the next (free!) Objective for the We #OFTW is ๐ฅ
๐ Berlin
๐๏ธ July 30โ31, 2026
Join us! ๐คฉ
Only ~2 weeks left to apply:
https://t.co/uDfGVDG0hR
โน๏ธ BlockBlock v2.5.0 adds a new feature that can alert you whenever a downloaded script is about to execute.
Designed to complement "Notarization" Mode, it provides an additional layer of protection against potentially unsafe content before it runs. ๐ก๏ธ
https://t.co/JFIPg35zZq
๐บNEW: Apple is expanding Private Cloud Compute (PCC) beyond our data centers. PCC on Google Cloud: NVIDIA Confidential Computing, Intel TDX, and Google's Titan chip, with capabilities that go far beyond a traditional confidential computing deployment. https://t.co/DF2Hw8HUZH
yasss, this is delightful ๐คฉ
Handling ES deadlines has always been complex(ish) (e.g. don't forget to use a mach_timebase_info when converting "mach time" to nanoseconds on Apple Silcon!) ๐ตโ๐ซ
...and if you got it wrong (and missed a deadline) the kernel would just kill you! โ ๏ธ
New macOS Backdoor "FlutterShell" ๐๐
Discovered & analyzed by @PaloAltoNtwks@Unit42_Intel ๐๐ผ
"weaponizes AI summarization features for data exfiltration by routing documents through an attacker-controlled server before processing them " ๐๐ฅ
https://t.co/mj6h27q3Ss
Stoked that @Rippling has joined our "Friends of Objective-See" program in support of our non-profit foundation ๐
Their support helps our:
๐ ๏ธ open-source tools
๐ free #TAOMM books
๐จโ๐ฉโ๐ฆ community-driven #OBTS/#OFTW events
...continue to grow & thrive!
https://t.co/rs89ZMdv47
You asked, we listened ๐
"DoNotDisturb" v2.1 adds 'Trusted Unlock' mode
When enabled, if a lid-open event is followed by a successful Touch ID or unlock via your Apple Watch, DND can ignore it, reducing false alarms while still watching for evil maids.
https://t.co/WHKNnDOsWb