Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem

YouTube-Video: Author: Black Hat - Bewertung: 0x - Views:4 macOS adoption in enterprise environments has surged in recent years, yet defensive tooling and…

0
↗ Quelle (youtube.com)
Reagiere als Erste:r — dein Feedback zählt!

Author: Black Hat - Bewertung: 0x - Views:4

macOS adoption in enterprise environments has surged in recent years, yet defensive tooling and public research still center heavily on Windows threats, leaving macOS malware underrepresented. To help bridge this gap, we introduce MALET, the largest public dataset of macOS malware to date (48.4k malicious / 22.9k benign Mach-O binaries), and Katalina, a new, open-source, high-performance static analysis tool capable of processing thousands of binaries per minute on commodity hardware.



Our talk distills 18 months of measurement into actionable insights for malware analysts, detection engineers, and incident responders. We show how 96% of macOS malware remains unsigned, and of the signed remainder, 38% use certificates that were later revoked often tied to DPRK APT infrastructure. These binaries evaded Gatekeeper and persisted for up to 721 days before revocation.



We surface 185 previously misclassified binaries that AV engines labeled benign despite sharing structural fingerprints with known malware. Static clustering using UUIDs, TeamIDs, and symbol hashes reveals four dominant macOS malware archetypes. We also show how rare entitlement combinations (e.g., com.apple.private.tcc.allow) appear 25x more often in malware, enabling stealth access to sensitive hardware like the microphone and camera.



We demonstrate how these findings can directly feed into resilient detection pipelines, including Sigma/YARA rule generation, a live triage workflow, and an extensible open-source toolchain. Attendees will leave with data, tooling, and practical heuristics they can apply immediately in their own environments.



By:

Obinna Igbe | Independent Researcher,

Godwin Attigah | Security Engineer, Airbnb



https://blackhat.com/eu-25/briefings/schedule/?#silence-on-macos-what-70k-binaries-reveal-about-the-macos-malware-ecosystem-49195

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem
id: 0c871771-ee4b-4ec2-a5aa-2144dbccf428
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "Black Hat Europe 2025 | Silenc" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Black Hat Europe 2025  Silence On macOS ")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Black Hat Europe 2025  Silence On macOS *"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Black Hat Europe 2025  Silence On macOS "
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Black Hat Europe 2025 | Silence On macOS.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem

Thematisch verwandte Begriffe: Black, Europe, 2025, Silence · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-63208 | Zammad is a web based open source helpdesk/customer support system. Prio…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag