VORANT. Threat Intelligence Sign in Get the full feed

DazzleSpy malware hits HK pro-democracy Mac users

high threat media

ESET-discovered macOS spyware DazzleSpy was delivered via a compromised Hong Kong radio station website to spy on pro-democracy visitors.

Researchers at ESET uncovered a watering-hole campaign in which a Hong Kong pro-democracy radio station's website was compromised to serve a WebKit/Safari exploit chain that silently installed a new macOS espionage implant dubbed DazzleSpy. Objective-See's analysis of the sample confirms the malware persists via a LaunchAgent (~/Library/LaunchAgents/com.apple.softwareupdate.plist) that relaunches the binary from ~/.local/softwareupdate, and communicates with a hardcoded C2 server at 88.218.192.128:5633.

Class-dump and disassembly reveal a full-featured cyber-espionage toolset: host survey (hardware/serial/OS version collection), file search by extension (targeting office documents), remote command execution, self-deletion, full interactive remote desktop via AVFoundation-based screen/video capture, and keychain dumping — the latter reportedly leveraging CVE-2019-8526, a keychain access flaw disclosed by researcher Linus Henze. The malware is an unsigned x86_64 Mach-O binary that runs under Rosetta2 on Apple Silicon.

Objective-See demonstrated that its free tools — BlockBlock (persistence detection), LuLu (outbound firewall), and KnockKnock (persistence scanner) — all detect DazzleSpy's activity without prior signatures, underscoring the value of behavioral detection against targeted implants like this one.

Mentioned in this report

Vulnerabilities CVE-2019-8526KEV
Malware DazzleSpy

Source reporting: https://objective-see.org/blog/blog_0x6D.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free