Real News, Fake Flash: Mac OS X Users Targeted
ID: b36aaa22-e190-59d3-b889-57fccc01b63a
STIX ID: report--b36aaa22-e190-59d3-b889-57fccc01b63a
Feed Name: Volexity Blog
Threat Score
Volexity identified that the Georgian-language section of a reputable media website was compromised to serve malicious JavaScript that targeted Mac OS X Safari users and redirected them to a fake "Flash Player Critical Update" page; this led to a user‑assisted download and installation of a signed OSX/Leverage backdoor which achieves persistence via a LaunchAgent and beacons to C2 servers (domains and IPs provided), with file hashes and detection guidance included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
