This report details a macOS malware infection involving the "Essential Stealer" malware. The attack begins with a deceptive webpage posing as a legitimate macOS software distribution site. Users are tricked into copying malicious commands from the fake site and pasting them into the macOS Terminal, which initiates the infection process on the host system.
The malware facilitates data theft and utilizes the Polygon blockchain as part of its command-and-control (C2) infrastructure. Network traffic analysis revealed active communication with the malicious server after execution. Forensic artifacts provided include PCAP files of the infection traffic and relevant malware files associated with the "Build POMP" variant.
Top comments (0)