DazzleSpy malware hits HK pro-democracy Mac users
ESET-discovered macOS spyware DazzleSpy was delivered via a compromised Hong Kong radio station website to spy on pro-democracy visitors.
Researchers at ESET uncovered a watering-hole campaign in which a Hong Kong pro-democracy radio station's website was compromised to serve a WebKit/Safari exploit chain that silently installed a new macOS espionage implant dubbed DazzleSpy. Objective-See's analysis of the sample confirms the malware persists via a LaunchAgent (~/Library/LaunchAgents/com.apple.softwareupdate.plist) that relaunches the binary from ~/.local/softwareupdate, and communicates with a hardcoded C2 server at 88.218.192.128:5633.
Class-dump and disassembly reveal a full-featured cyber-espionage toolset: host survey (hardware/serial/OS version collection), file search by extension (targeting office documents), remote command execution, self-deletion, full interactive remote desktop via AVFoundation-based screen/video capture, and keychain dumping — the latter reportedly leveraging CVE-2019-8526, a keychain access flaw disclosed by researcher Linus Henze. The malware is an unsigned x86_64 Mach-O binary that runs under Rosetta2 on Apple Silicon.
Objective-See demonstrated that its free tools — BlockBlock (persistence detection), LuLu (outbound firewall), and KnockKnock (persistence scanner) — all detect DazzleSpy's activity without prior signatures, underscoring the value of behavioral detection against targeted implants like this one.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x6D.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free