This report documents an infection involving the "Essential macOS Stealer" malware, detailing a campaign that targets macOS users through social engineering. The attack chain involves a deceptive web page masquerading as legitimate software, which prompts victims to execute malicious commands directly within the macOS Terminal.
Technical analysis of the infection reveals that the malware utilizes the Polygon blockchain to manage its command-and-control (C2) server information. The provided artifacts include network traffic captures (PCAPs), infection files, and screenshots demonstrating the terminal command execution and blockchain transaction data used for infrastructure resolution.
Top comments (0)