logo

EvilOSX

ID: b208ef74-bdd2-5e79-b57a-84946c15db04

STIX ID: report--b208ef74-bdd2-5e79-b57a-84946c15db04

Feed Name: Binary Defense Blog

Threat Score
55/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

EvilOSX is a newly released macOS Remote Access Trojan available on GitHub that is under active development and includes AV-evasion tactics (random comment insertion and base64+OpenSSL self-encryption to change file hashes), modular capabilities for data theft (Chrome passwords, browser history), file management, persistence, a local privilege escalation leveraging CVE-2015-5889, and limited DoS functionality; the repository indicates active author efforts to bypass antivirus detection, but at the time of reporting there is no clear evidence of large-scale distribution or centralized command-and-control for mass compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.