logo

Real News, Fake Flash: Mac OS X Users Targeted

ID: b36aaa22-e190-59d3-b889-57fccc01b63a

STIX ID: report--b36aaa22-e190-59d3-b889-57fccc01b63a

Feed Name: Volexity Blog

Threat Score
70/100

Date Published: 2017-07-24

Date Updated: 2026-05-01

...
...

Volexity identified that the Georgian-language section of a reputable media website was compromised to serve malicious JavaScript that targeted Mac OS X Safari users and redirected them to a fake "Flash Player Critical Update" page; this led to a user‑assisted download and installation of a signed OSX/Leverage backdoor which achieves persistence via a LaunchAgent and beacons to C2 servers (domains and IPs provided), with file hashes and detection guidance included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.