216.73.217.22

LightSpy Malware Variant Targeting macOS

· Published 29/04/2024 18:41 · Modified 01/05/2024 23:07

Export JSON

Essential information

Published
29/04/2024 18:41
Modified
01/05/2024 23:07
Tags
dropper implant lightspy macos plugins
Related entities
12 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware

Description

This report details the discovery of a variant of the malware, previously known to target iOS and Android devices. The consists of a that downloads and runs a core dylib, which in turn loads various to accomplish malicious tasks. The report provides a technical analysis of the malware components, including the droppers, implants, and , highlighting key differences from the iOS version. It also discusses the communication with the command-and-control (C2) server and the data collection capabilities of the malware. The report aims to raise awareness about the evolving threats targeting the platform.

External references