LightSpy Spyware's macOS Variant Found with Advanced Surveillance Capabilities
ID: 89928d41-42a7-596e-94c8-5813936c0327
STIX ID: report--89928d41-42a7-596e-94c8-5813936c0327
Feed Name: The Hacker News
LightSpy researchers have identified a previously undocumented macOS variant of the LightSpy spyware active since at least January 2024. The attack chain exploits CVE-2018-4233 (Safari/WebKit) and CVE-2018-4404 to drop a 64-bit Mach-O masquerading as a PNG which launches a shell script to fetch a privilege escalation exploit, crypto utility, and a ZIP containing an "update" loader and plist for persistence. The loader (macircloader) contacts C2 to retrieve commands and dynamically load up to ten plugins capable of recording audio, taking photos, capturing the screen, harvesting files and browser/iCloud Keychain data, executing shell commands, and performing network discovery; researchers also found a misconfigured C2 panel exposing victim data. Although technically sophisticated, observed infections are small in number (~20 devices, many test systems), but the implant’s capabilities make it a high-risk targeted espionage tool.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
