216.73.216.226

New Mac malware identified that evades detection through fake PDF conversion tool

· Published 29/08/2025 20:19 · Modified 01/09/2025 08:59

Export JSON

Essential information

Published
29/08/2025 20:19
Modified
01/09/2025 08:59
Tags
2025-08-29 apple security browser redirection chrome hijacking fileripple.com jscorerunner mac mosyle pdf conversion two-stage infection zero-day threat
Related entities
5 techniques (mitre), 1 malware

Description

has discovered a new malware strain called '' that evades detection by masquerading as a tool. The malware spreads through a malicious website, , and operates in two stages. The first stage, FileRipple.pkg, appears as a legitimate PDF tool while running malicious code in the background. The second stage, Safari14.1.2MojaveAuto.pkg, bypasses Gatekeeper's protections. Once installed, targets Chrome browsers, altering search engine settings to redirect users to fraudulent providers. This exposes users to keylogging, phishing, and potential data theft. The malware's sophisticated approach highlights the need for vigilance and proactive security measures for administrators.

External references