Threat Intelligence: New LamePyre Mac Malware
ID: 2a2dca1b-6761-54e4-a714-14878a3fd8b6
STIX ID: report--2a2dca1b-6761-54e4-a714-14878a3fd8b6
Feed Name: Binary Defense Blog
Threat Score
LamePyre is a recently identified macOS malware that poses as Discord but is actually a rudimentary shell which decodes a payload, captures screenshots, and sends them to a C2 server. It persists using a launch agent named com.apple.systemkeeper.plist; researchers note it is poorly disguised and currently of limited capability, but users should be cautious about downloaded apps and permissions since the malware could be extended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
