logo

How to Phish for Geniuses

ID: bd4b9533-e461-5ccf-9796-f054895040fc

STIX ID: report--bd4b9533-e461-5ccf-9796-f054895040fc

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-01-03

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates a technique for delivering malware to macOS hosts by creating a macOS installer package that contains a postinstall script (generated from an EmPyre bash stager) which runs on installation (often with root privileges). The author details building the package with pkgbuild --nopayload and a scripts folder, shows screenshots of the installer and C2 callback, and highlights using osascript popups to deceive users; the write-up is a proof-of-concept / offensive technique rather than an observed attack campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.