Beyond the wail: deconstructing the BANSHEE infostealer
ID: e5669cff-ed0e-5198-b20e-b5ed1aeb3559
STIX ID: report--e5669cff-ed0e-5198-b20e-b5ed1aeb3559
Feed Name: Elastic Security Labs
Threat Score
BANSHEE Stealer is a newly observed macOS infostealer (x86_64 and ARM64) that collects system info, browser data (cookies, history, logins, ~100 extensions), keychain passwords, and various cryptocurrency wallets, then compresses, XOR-encodes, and exfiltrates the data to a remote C2; the analysis includes anti-debug/VM/language checks, AppleScript-based credential prompting, YARA rules, and observables (SHA-256 and C2 IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
