How to Phish for Geniuses
ID: bd4b9533-e461-5ccf-9796-f054895040fc
STIX ID: report--bd4b9533-e461-5ccf-9796-f054895040fc
Feed Name: Black Hills Infosec Blog
This report demonstrates a technique for delivering malware to macOS hosts by creating a macOS installer package that contains a postinstall script (generated from an EmPyre bash stager) which runs on installation (often with root privileges). The author details building the package with pkgbuild --nopayload and a scripts folder, shows screenshots of the installer and C2 callback, and highlights using osascript popups to deceive users; the write-up is a proof-of-concept / offensive technique rather than an observed attack campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
