Tuesday, November 12, 2024
HomeCVE/vulnerabilitymacOS Infostealers That Actively Involve in Attacks Evade XProtect Detection

macOS Infostealers That Actively Involve in Attacks Evade XProtect Detection

Published on

Malware protection

Ever since the beginning of 2023, infostealers targeting macOS have been on the rise with many threat actors actively targeting Apple devices. As of last year, many variants of Atomic Stealer, macOS meta stealer, RealStealer, and many others were discovered.

However, Apple updated their built-in antivirus “XProtect” signature databases in macOS which denotes that Apple is completely aware of these info stealers and has been taking necessary measures to prevent them. On the other side, threat actors have been constantly evolving and evading known signatures.

Document
Free Webinar

Fastrack Compliance: The Path to ZERO-Vulnerability

Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.

- Advertisement - SIEM as a Service

Technical Analysis – The Three Active Infostealers

According to the reports shared with Cyber Security News, Keysteal, Atomic InfoStealer, and CherryPie were three active infostealers that presently evade many static signature detection engines including XProtect. 

KeySteal

This stealer was first discovered in 2021 and has been constantly evolving with evasion techniques. Some of the distributions of this malware were under the binary name “ChatGPT”. Apple added a signature for this malware in 2023 inside XProtect which no longer works.

Recent sample of KeySteal
Recent sample of KeySteal (Source: SentinelOne)

During the initial stages of this Keysteal, it was distributed with a .pkg format embedded inside the “ReSignTool” macOS utility. It is coded in such a way to steal Keychain information which holds a lot of sensitive password information and establish persistence on the affected device.

The latest version of KeySteal replaces “ReSignTool” with multi-architecture Mach-O binaries under the names “UnixProject” and “ChatGPT”. The malware is written in Objective C and current distribution methods are unclear.

Atomic Infostealer

Apple updated their XProtect Signature databases for detecting this malware earlier this month. But it seems like threat actors have up-to-date information about the signature detection and have modified the malware with a Go language version shortly after the signature update.

In addition to this, this malware has been seen with completely different development chains, unlike other infostealers which update only the core version. There have been several variations of this malware currently in the wild attacking macOS devices.

The malware is written in C++ and consists of logic to prevent victims, analysts, or malware sandboxes from running the terminal in parallel with the stealer. Furthermore, it also checks if the malware is being tested inside a virtual machine.

The distributions of this malware were through torrents or gaming-focused social media platforms appearing as a “CrackInstaller” with the .dmg format. 

GateKeeper Override by Atomic Stealer
GateKeeper Override by Atomic Stealer (Source: SentinelOne)

CherryPie

This infostealer malware is also known as Gary Stealer or “JaskaGo” which is a cross-platform malware written in Go with extensive logic for anti-analysis and VM detection. However, the malware developers seem too confident that they left extremely obvious strings which indicate the core intent and purpose of this malware.

CherryPie attempts to disable GateKeeper
CherryPie attempts to disable GateKeeper (Source: SentinelOne)

In some samples, there were traces of using the Wails project for bundling their malicious application. During the execution of this malware, the application calls the spctl utility with the –master-disable argument for disabling the Gatekeeper and runs with administrative privileges.

Furthermore, a complete report about this malware has been published which provides detailed information about the source code, behavior, intent, and other information. 

Indicators of Compromise

KeySteal

  • 95d775b68f841f82521d516b67ccd4541b221d17
  • f75a06398811bfbcb46bad8ab8600f98df4b38d4
  • usa[.]4jrb7xn8rxsn8o4lghk7lx6vnvnvazva[.]com

Atomic InfoStealer

  • 1b90ea41611cf41dbfb2b2912958ccca13421364
  • 2387336aab3dd21597ad343f7a1dd5aab237f3ae
  • 8119336341be98fd340644e039de1b8e39211254
  • 973cab796a4ebcfb0f6e884025f6e57c1c98b901
  • b30b01d5743b1b9d96b84ef322469c487c6011c5
  • df3dec7cddca02e626ab20228f267ff6caf138ae

CherryPie

  • 04cbfa61f2cb8daffd0b2fa58fd980b868f0f951
  • 09de6c864737a9999c0e39c1391be81420158877
  • 6a5b603119bf0679c7ce1007acf7815ff2267c9e
  • 72dfb718d90e8316135912023ab933faf522e78a
  • 85dd9a80feab6f47ebe08cb3725dea7e3727e58f
  • 104[.]243[.]38[.]177

Looking for cost-effective penetration testing services? Try Kelltron’s to assess and evaluate the security posture of digital systems – 

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Tor Network Suffers IP Spoofing Attack Via Non-Exit Relays

In late October 2024, a coordinated IP spoofing attack targeted the Tor network, prompting...