Stealthy New macOS Backdoor Hides on Chinese Websites
ID: 0dc85a7e-07e6-52c4-a2f4-2310204ce98d
STIX ID: report--0dc85a7e-07e6-52c4-a2f4-2310204ce98d
Feed Name: Dark Reading
Date Published: 2024-01-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Jamf Threat Labs found trojanized macOS applications hosted on Chinese pirating sites that contain a hidden ".fseventsd" binary and malicious dylib which drop a Khepri-derived backdoor and a downloader. The malware establishes persistence, collects system information, supports file upload/download and remote shells, and uses stealth techniques (renaming, hiding) to evade detection; users should avoid pirated apps and deploy macOS-focused detection and web filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
