logo

MacOS info-stealers quickly evolve to evade XProtect detection

ID: 71c46f85-09ff-5b3a-951f-acbf7972a0af

STIX ID: report--71c46f85-09ff-5b3a-951f-acbf7972a0af

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SentinelOne's report highlights three macOS info-stealers — KeySteal, Atomic Stealer, and CherryPie — that actively evade detection by Apple's XProtect and many antivirus products through rapid evolution, anti-analysis techniques, and persistence mechanisms; they target Keychain credentials, can disable Gatekeeper, and employ anti-VM and obfuscation strategies. While Apple has updated some XProtect signatures, detection remains inconsistent, and the report recommends defenses beyond static signatures, including dynamic/heuristic AV, network monitoring, firewalls, and timely patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.