logo

Sinking macOS Pirate Ships with Elastic Behavior Detections

ID: 45170ee8-1e1d-50c9-83ba-786054e74d91

STIX ID: report--45170ee8-1e1d-50c9-83ba-786054e74d91

Feed Name: Elastic Security Labs

Threat Score
65/100

Date Published: 2024-03-15

Date Updated: 2026-04-27

...
...

Elastic researchers analyzed a macOS malware campaign delivered through a pirated UltraEdit .dmg that loads an unsigned libConfigurer64.dylib to drop two hidden payloads: /private/tmp/.test (a Khepri-based backdoor) and /Users/Shared/.fseventsd (a masqueraded launch-agent persistence/downloader). Instead of deep internals, the report focuses on practical, resilient behavior-based detections and threat-hunting guidance using macOS Endpoint Security Framework data and Elastic Agent (EQL/ES|QL), providing example rules to detect unsigned dylib loads, hidden executables, suspicious outbound connections, malicious launch plist creation, and hidden executable creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.