Sinking macOS Pirate Ships with Elastic Behavior Detections
ID: 45170ee8-1e1d-50c9-83ba-786054e74d91
STIX ID: report--45170ee8-1e1d-50c9-83ba-786054e74d91
Feed Name: Elastic Security Labs
Elastic researchers analyzed a macOS malware campaign delivered through a pirated UltraEdit .dmg that loads an unsigned libConfigurer64.dylib to drop two hidden payloads: /private/tmp/.test (a Khepri-based backdoor) and /Users/Shared/.fseventsd (a masqueraded launch-agent persistence/downloader). Instead of deep internals, the report focuses on practical, resilient behavior-based detections and threat-hunting guidance using macOS Endpoint Security Framework data and Elastic Agent (EQL/ES|QL), providing example rules to detect unsigned dylib loads, hidden executables, suspicious outbound connections, malicious launch plist creation, and hidden executable creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
