Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Nice, I've found an infostealer in the wild!

Nice, I've found an infostealer in the wild!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
threatintelmacoscybersecurity
2 Indlæg 2 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jtig@infosec.exchangeJ This user is from outside of this forum
    jtig@infosec.exchangeJ This user is from outside of this forum
    jtig@infosec.exchange
    wrote sidst redigeret af
    #1

    Nice, I've found an infostealer in the wild!

    This repo just has some info and a download button for a paid macOS app.

    It links to hxxps://za-loop-osx-software[.]github[.]io/.github/RoyalTSX, which redirects you to hxxps://github[.]topic-developer[.]com/packages.html, which tells you to run a curl command and pipe it into bash, encoded in a base64 string.

    The curl command grabs a file from 217[.]119[.]139[.]117, which looks like an infostealer and some other malware written in AppleScript.

    Have fun SOC people.

    #threatintel #macos #cybersecurity

    mjack@mastodon.bsd.cafeM 1 Reply Last reply
    0
    • jtig@infosec.exchangeJ jtig@infosec.exchange

      Nice, I've found an infostealer in the wild!

      This repo just has some info and a download button for a paid macOS app.

      It links to hxxps://za-loop-osx-software[.]github[.]io/.github/RoyalTSX, which redirects you to hxxps://github[.]topic-developer[.]com/packages.html, which tells you to run a curl command and pipe it into bash, encoded in a base64 string.

      The curl command grabs a file from 217[.]119[.]139[.]117, which looks like an infostealer and some other malware written in AppleScript.

      Have fun SOC people.

      #threatintel #macos #cybersecurity

      mjack@mastodon.bsd.cafeM This user is from outside of this forum
      mjack@mastodon.bsd.cafeM This user is from outside of this forum
      mjack@mastodon.bsd.cafe
      wrote sidst redigeret af
      #2

      @jtig

      Clever bait, for an infostealer.

      1 Reply Last reply
      0
      Svar
      • Svar som emne
      Login for at svare
      • Ældste til nyeste
      • Nyeste til ældste
      • Most Votes


      • Log ind

      • Har du ikke en konto? Tilmeld

      • Login or register to search.
      Powered by NodeBB Contributors
      Graciously hosted by data.coop
      • First post
        Last post
      0
      • Hjem
      • Seneste
      • Etiketter
      • Populære
      • Verden
      • Bruger
      • Grupper