MacOS info-stealers quickly evolve to evade XProtect detection
ID: 71c46f85-09ff-5b3a-951f-acbf7972a0af
STIX ID: report--71c46f85-09ff-5b3a-951f-acbf7972a0af
Feed Name: Bleeping Computer
SentinelOne's report highlights three macOS info-stealers — KeySteal, Atomic Stealer, and CherryPie — that actively evade detection by Apple's XProtect and many antivirus products through rapid evolution, anti-analysis techniques, and persistence mechanisms; they target Keychain credentials, can disable Gatekeeper, and employ anti-VM and obfuscation strategies. While Apple has updated some XProtect signatures, detection remains inconsistent, and the report recommends defenses beyond static signatures, including dynamic/heuristic AV, network monitoring, firewalls, and timely patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
