logo

macOS Malware Campaign Showcases Novel Delivery Technique

ID: 78404e09-202a-5f6d-ba12-c58527e385d4

STIX ID: report--78404e09-202a-5f6d-ba12-c58527e385d4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-02-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers (Kaspersky and SentinelOne) have uncovered the 'Activator' macOS backdoor campaign that distributes malware via cracked copies of popular applications. Attackers supply an unusable cracked app plus an 'Activator' helper that prompts for admin credentials to disable Gatekeeper, turns off notifications, installs a Launch Agent, and launches a Python-based backdoor (running from memory) which serves as a first-stage downloader; SentinelOne observed a high volume of unique samples across many cracked-app lures (roughly 70 distinct applications), raising concerns about widespread infections and a potential macOS botnet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.