macOS version of elusive 'LightSpy' spyware tool discovered
ID: f99da4f9-4de3-5adf-b4ce-b84587e8f722
STIX ID: report--f99da4f9-4de3-5adf-b4ce-b84587e8f722
Feed Name: Bleeping Computer
ThreatFabric discovered a macOS implant for the LightSpy modular surveillance framework (active since at least Jan 2024) that uses WebKit exploits to drop staged payloads, escalate privileges, establish persistence, and load a core plugin manager which executes plugins to capture audio, screen, camera, keychain, files, network info and more; researchers accessed the attackers' control panel revealing infected hosts and potential implants for other platforms, though current macOS deployment appears limited and partially used in testing environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
