“Matryoshka” Malware: New macOS Attack Hides Inside “Russian Dolls” of Obfuscation
ID: 90adf904-1e52-538f-898c-6c714e547e63
STIX ID: report--90adf904-1e52-538f-898c-6c714e547e63
Feed Name: securityonline.info
Matryoshka is a macOS-targeting social-engineering campaign that lures cryptocurrency users from typo-squatted sites through a Traffic Distribution System, instructs victims to paste a 'fix' command into Terminal, and installs a heavily obfuscated, in-memory stealer. The malware employs nested obfuscation and API-gated communications to evade detection, harvests browser data, and surgically tampers with or replaces wallet application components (notably Ledger Live and Trezor Suite) to exfiltrate funds while presenting fake error messages to delay discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
