EvilOSX
ID: b208ef74-bdd2-5e79-b57a-84946c15db04
STIX ID: report--b208ef74-bdd2-5e79-b57a-84946c15db04
Feed Name: Binary Defense Blog
EvilOSX is a newly released macOS Remote Access Trojan available on GitHub that is under active development and includes AV-evasion tactics (random comment insertion and base64+OpenSSL self-encryption to change file hashes), modular capabilities for data theft (Chrome passwords, browser history), file management, persistence, a local privilege escalation leveraging CVE-2015-5889, and limited DoS functionality; the repository indicates active author efforts to bypass antivirus detection, but at the time of reporting there is no clear evidence of large-scale distribution or centralized command-and-control for mass compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
