Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

NovaStealer - Apple Intelligence is leaving a plist.. it is legit, right?

released on 2025-11-14 @ 12:04:56 PM
A cryptostealer for macOS utilizes a bash-based script to establish persistence and execute malicious modules. The malware installs itself in the ~/.mdrivers directory, uses screen sessions for background execution, and employs a LaunchAgent for persistence. It exfiltrates crypto wallet data, collects system information, and replaces legitimate wallet applications with malicious versions. The threat actor employs clever techniques like using WebKit to render phishing pages and tracking user behavior. While not highly sophisticated, the modular nature and ability to update components remotely make it a noteworthy threat.