Objective-See Catalogs 2021's New macOS Malware
Objective-See's annual roundup details seven new 2021 macOS malware families—ElectroRAT, SilverSparrow, XcodeSpy/EggShell, ElectrumStealer, WildPressure, XLoader, and ZuRu—covering RATs, stealers, and backdoors.
This is Objective-See's sixth annual comprehensive review of new macOS malware, compiling and re-analyzing specimens first reported by various AV vendors throughout 2021, complete with downloadable samples and technical breakdowns of infection vectors, persistence, and capabilities. Highlights include OSX.ElectroRAT, a Go-based cross-platform RAT distributed via trojanized fake cryptocurrency trading apps that embeds camera-capture, Chrome password-stealing, keylogging, and VNC tools and calls out to pastebin for C2 discovery; OSX.SilverSparrow, a mysterious payload-less M1-native dropper that infected roughly 30,000 Macs via unknown delivery of malicious .pkg installers using the macOS Installer JavaScript API; and OSX.XcodeSpy, which poisons open-source Xcode projects with a hidden build script to drop a custom EggShell backdoor onto developer machines — an early example of a software supply-chain-style attack on macOS.
Other entries include OSX.ElectrumStealer, a backdoored Electrum wallet clone that was inadvertently notarized by Apple and distributed via malvertising/fake update prompts to steal cryptocurrency wallets and passwords; a macOS port of WildPressure, a cross-platform Python backdoor with suspected limited targeting of Middle East oil-and-gas users; XLoader, the macOS-capable evolution of the FormBook stealer sold as MaaS and distributed via phishing (including malicious .jar attachments), which harvests Firefox and Chrome credentials; and OSX.ZuRu, distributed through malicious Baidu sponsored search ads mimicking legitimate app sites (e.g., iTerm), which conducts extensive system reconnaissance/exfiltration before dropping a Cobalt Strike agent.
Collectively the post underscores growing macOS targeting as Apple gains enterprise market share, with infection vectors ranging from trojanized applications and malvertising to subverted developer tooling and MaaS phishing kits. No single campaign is attributed to a named threat actor with confidence; WildPressure is noted as likely targeted at Middle East oil and gas organizations, while the rest largely target general cryptocurrency users, developers, and broad Chinese-language search traffic.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x6B.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free