HomeSecurityMacOS info-stealer malware evades detection by XProtect

MacOS info-stealer malware evades detection by XProtect

Many info-stealer malware targeting macOShave features that allow them to evade detection, although more and more companies are reporting new malware variants they are detecting.

MacOS info stealer

SentinelOne researchers have described three known macOS malware that can evade the built-in malware protection system, XProtect .

XProtect works in the background while scanning downloaded files and applications to warn users of potential malicious activity.

Despite the fact that Apple constantly updates the tool's database with new malware samples that are detected, SentinelOne says that some info-stealers bypass it almost immediately, thanks to the quick response of the malware creators.

See also: Atomic Stealer: New version of malware targets macOS

How MacOS info-stealer malware evade XProtect?

The first example reported by SentinelOne is KeySteal, a malware first detected in 2021. It has since evolved significantly and is now distributed as an Xcode-built Mach-O binary, under the name “UnixProject” or “ChatGPT.” Its goal is to establish persistence and steal Keychain.

Keychain is macOS's native password management system that allows for secure storage of credentials, private keys, certificates, and notes .

Apple last updated its database regarding KeySteal in February 2023. However, researchers say that the info-stealer malware has undergone changes since then to go unnoticed by XProtect and most AV engines.

Its only current weakness is the use of hardcoded command and control (C2) addresses. However, this does not mean anything, as its creators may soon implement a rotation mechanism.

See also: SpectralBlur: A new backdoor targeting macOS systems

The next macOS info-stealer malware is the Atomic Stealer . Apple last updated its XProtect signatures and detection rules this month, but researchers have observed C++ variants that can still evade detection.

The latest version of Atomic Stealer has replaced code obfuscation with clear text AppleScript that exposes the data-stealing logic, includes anti-VM checks, and prevents Terminal from running alongside it.

Finally, another malware that evades detection is CherryPie, also known as “Gary Stealer” or “JaskaGo.” It is the newest of the three (appeared in September 2023).

The malware targets multiple platforms and features analysis and detection evasion capabilities such as Wails wrapping, ad hoc signatures, and a system that disables Gatekeeper using administrator privileges.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

XProtect
MacOS info-stealer malware evades detection by XProtect

Apple updated the XProtect signatures for the CherryPie info-stealer malware in early December 2023 , and they work very well even for newer variants. However, malware detections don't fare as well in Virus Total.

The above shows that more and more cybercriminals are creating macOS malware that is resistant to detection and bypasses device security systems

Static detection methods for security are not enough. A more robust approach should incorporate antivirus software equipped with advanced analysis capabilities.

See also: Info-stealer malware targets the online gaming community

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install MacOS info-stealers.

Also, don't forget to use firewalls and monitor network traffic , which will help you immediately identify suspicious activity.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to account , even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS