Want to go deeper? 🔎
Explore the full Moonlock Lab mid-2026 macOS Threat Report, including threat data, attack trends, and recommendations for Mac users and security teams:
https://t.co/wVd1YGYNv0
1/ Looks like #DigitStealer is still hard to detect on VT. @malwrhunterteam shared a file with us which led to Stage-1 compiled AppleScript. With multiple parallel scripts to execute, it remains a threat to #macOS users.
More info below 👇
Meet CrashStealer. This one takes delivery more seriously than most, a signed and Apple-notarized dropper that's pulling its second stage payload down through GitHub.
The payload is a native C++ stealer with client-side AES-GCM encryption and layered anti-analysis.
Check out our writeup for additional details and indicators of compromise.
https://t.co/3IhuEmrsZj
#infostealer #malware #macos #threatresearch
Apple Intelligence is changing how millions interact with AI.
But how does it actually work under the hood? 🔥
We're thrilled to welcome Bhargav Rathod, Staff Analyst at Palo Alto Networks Unit 42, as a speaker at Upwind presents BSides Ahmedabad 0x7.
In his session, "Apple Intelligence Exposed: Reverse Engineering the AI Assistant," Bhargav will explore the architecture behind Apple's AI assistant, the techniques used to reverse engineer it, and the security insights that emerge from understanding its inner workings.
If AI security and reverse engineering are on your radar, this is a session you won't want to miss.
📍 Hyatt Regency, Ahmedabad
📅 26–27 September 2026
🎟️ Your seat is waiting. Book your spot: https://t.co/ppHZdsuaUv
#BSidesAhmedabad #BSidesAhmedabad0x7 #UpwindPresentsBSidesAhmedabad #AppleIntelligence #ReverseEngineering #AISecurity #Unit42 #CyberSecurity #InfoSec
Had fun digging into this!
The Clickfix tactic appears similar to what has been observed with Shalyer and the infostealer family looks like a variant of AMOS and Poseidon stealer
#macos#malware
The latest macOS ClickFix variant invisibly mounts DMG images in the background to execute a macOS infostealer and hijack cryptocurrency wallet info. Details at https://t.co/8Bg5ojzg26
🍎🌁 Big changes to user TCC.db in macOS Golden Gate! It seems that it finally got the protection it deserves.
It was moved to:
/private/var/containers/Data/ProtectedSystem/[UUID]/Data/Library/Application Support/com.apple.TCC/
You can't access it even with FDA, and likely need "com\.apple.private.security.protected-system-container" entitlement to write to it.
The power of Phorion Protections is nuts 🔥 Being built into the EDR gives you full historical analytics on any file/process controls that you implement.
Prevent anomalous activity wherever you can, and where you can’t - have the detections in place to catch edge cases.
BlockBlock vs. https://t.co/TxGjyWiHba 🙅🏻♂️🛡️🐱
BlockBlock (https://t.co/JFIPg35zZq) alerts on persistence events, including the persistent payload from the Nx Console VS Code compromise that impacted @github 👀
1/ℹ️We found a fully-featured macOS #RAT that zero AV vendors detected at the time of discovery.
Meet "3Crypt RAT/C2 Capability Tester" - a #macOS binary with deep recon, persistence, evasion, and lateral movement capabilities.
No real C2 infra. But don't let that fool you. 👇
🇰🇵 #Lazarus is back with a new macOS malware kit.
👷 Made up of multiple Mach-O binaries, we named it “Mach-O Man”. It is being distributed via #ClickFix in the crypto ecosystem to steal secrets.
▶️ Read my full article for ANY RUN below.
#DPRK#Malware
Found a macOS TOCTOU bug while reviewing Apple EDR integrations at @HuntressLabs.
A non-admin user can delete TCC-protected content by hitting the right timing window. Came up unexpectedly during the review, which made it a fun one.
New research from our friends/supporters @MacPaw / @moonlock_lab 👏
🍎👾🔬 New macOS stealer “notnullosx”: Go-based, modular, and going after everything from browser creds to crypto wallets.
Read: https://t.co/FfZWejZmPq
ClickFix techniques are evolving.
Instead of copy and paste instructions to Terminal, newer variants are using Script Editor to execute payloads on macOS.
Read more about this delivery technique in our latest blog post.
https://t.co/NBNlMqcRF6
#clickfix#malware#threathunting
Just released: BlockBlock v2.4
🆕 Notarization Mode ('All')
Blocks any non-notarized program (even those w/o quarantine attributes).
🆕 Heuristics for 'ClickFix'
Applies heuristics against pastes into terminals, blocking those deemed suspicious.
https://t.co/JFIPg367OY
Bhargav Rathod (Palo Alto Networks) leads a hands-on macOS forensics workshop at DFRWS APAC 2025. Learn practical techniques to investigate Apple devices in real-world cases.
👉 Check out the full program schedule and reserve your seat today: https://t.co/YfQfqsvD1C
I'm thrilled to announce that, I'll be presenting my research on "macOS Lockdown Mode" at the best DFIR event of the year!
#macos#dfir#digitalforensics#Apple#sans
Join us at #DFIRSummit when @malwr4n6 dives into how macOS Lockdown Mode reshapes #DigitalForensics — what’s restricted, what changes, & what artifacts #DFIR pros can still uncover.
🗓️ Summit: Jul 24-25
📍 Salt Lake City & Free Live Online
➡️ Register: https://t.co/8xAvn3Har6