logo

Stealthy New macOS Backdoor Hides on Chinese Websites

ID: 0dc85a7e-07e6-52c4-a2f4-2310204ce98d

STIX ID: report--0dc85a7e-07e6-52c4-a2f4-2310204ce98d

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Jamf Threat Labs found trojanized macOS applications hosted on Chinese pirating sites that contain a hidden ".fseventsd" binary and malicious dylib which drop a Khepri-derived backdoor and a downloader. The malware establishes persistence, collects system information, supports file upload/download and remote shells, and uses stealth techniques (renaming, hiding) to evade detection; users should avoid pirated apps and deploy macOS-focused detection and web filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.