A new macOS version of the LightSpy malware expands the reach of the surveillance framework, which until now was mainly known for targeting Android and iOS devices.

LightSpy is a modular surveillance framework that steals various data from users' devices, including files, screenshots, location, audio recordings, payment information, and data from messaging and social media apps.
The attackers behind LightSpy are using it in attacks against targets in the Asia-Pacific region.
According to a new report from ThreatFabric, the new macOS version has been in use since at least January 2024. However, its operation appears to be currently limited to testing environments.
See also: LightSpy iPhone spyware: Is it linked to APT41 hackers?
Researchers infiltrated the LightSpy control panel, exploiting a misconfiguration that allowed unauthorized access to the interface. This allowed them to gain information about its operation, infrastructure, and infected devices.
LightSpy malware: Exploiting vulnerabilities to compromise macOS systems
Attackers are exploiting WebKit vulnerabilities CVE-2018-4233 and CVE-2018-4404 to execute code within the Safari browser, targeting macOS 10.13.3 and earlier versions.

How does infection occur?
Initially, a 64-bit MachO binary disguised as a PNG (“20004312341.png”) is delivered to the device. It decrypts and executes embedded scripts that retrieve a second-stage payload.
The second-stage payload downloads a privilege escalation exploit (“ssudo”), an encryption/decryption utility (“ddss”), and a ZIP file (“mac.zip”) containing two executable files (“update” and “update.plist”).
Finally, the shell script decrypts and unpacks these files, gaining root access to the device and establishing persistence on the system by setting the “update” binary to run at boot.
The next step is performed by a component called “macircloader”, which downloads, decrypts, and executes the LightSpy Core.
This acts as the central management system for the LightSpy spyware framework and is responsible for communications with the command and control (C2) server. The LightSpy core also executes shell commands on the device.
See also: LightSpy malware actively targets MacOS devices
LightSpy plugins
The LightSpy malware extends its spying functionality using various plugins, which are responsible for different actions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This new macOS version of LightSpy uses ten plugins:
soundrecord: Records sound from the microphone.
ScreenRecorder : Records device screen activity
browser: Extracts browsing data from web browsers.
wifi: Collects data on Wi-Fi to which the device is connected.
cameramodule : Takes photos using the device's camera
FileManage: Manages and exports files, especially from messaging apps.
keychain: Retrieves sensitive information stored in the macOS Keychain.
LanDevices: Collects information about devices on the same local network.
softlist: Displays installed applications and running processes.
ShellCommand: Executes shell commands on the infected device.
Thanks to all these plugins, the LightSpy malware can steal many different data from infected macOS systems.
See also: Proactive detection and treatment of malware

macOS malware protection
Apple offers some built-in security features, such as Gatekeeper and XProtect to prevent infection.
But there are some other methods of protection:
- Keep your operating system and software up to date to patch any known vulnerabilities
- Be cautious when downloading and opening attachments or files from unknown sources
- Use a reliable antivirus software, especially if you frequently download files from the Internet.
- Enable FileVault, which encrypts data and protects it in case of theft or unauthorized access.
- Regularly back up your important files to an external hard drive
Source: www.bleepingcomputer.com
