216.73.217.22

Melting Pot of macOS Malware Adds Go to Crystal, Nim and Rust Variants

· Published 26/03/2025 15:23 · Modified 26/03/2025 17:21

Export JSON

Essential information

Published
26/03/2025 15:23
Modified
26/03/2025 17:21
Tags
2025-03-26 adware crystal dolittle genieo go loader macos malware nim persistence readerupdate rust silver toucan updateagent wizardupdate
Related entities
12 observables, 11 techniques (mitre), 6 malware

Description

, a platform active since 2020, has evolved to include variants written in , , , and now programming languages. Originally a compiled Python binary, the has been largely dormant until late 2024. The is capable of executing remote commands, potentially offering Pay-Per-Install or -as-a-Service. It collects system information, creates mechanisms, and communicates with command and control servers. The variant, less common than others, uses string obfuscation techniques to hinder analysis. While currently associated with delivery, the 's capabilities pose a potential threat for more malicious payloads in the future.

External references