Skip to content

Tag

malware

MacSync: when the victim types the attack chain

No exploit. No attachment. No phishing email. In this campaign the threat actor needs the victim to do exactly one thing: copy a command from an installation guide and paste it into the macOS Terminal. In the summer of 2026 our SOC intercepted that moment three times, on the same corporate endpoint, and blocked it three times. The target: a developer’s Mac. The payload: MacSync, an infostealer sold as Malware-as-a-Service and built for the Apple ecosystem

Read the analysis
·Emerging Threats

Cyber Attack Risk: Follina

Risks and Solutions How to protect and how to react The identification of this type of compromise can occur on different levels: Fortgale recommends performing proactive threat hunting activities to identify this type of compromise potentially undetected by the systems mentioned above. Choose the solution that best fit your company

Read the analysis
·Emerging Threats

CloudMensis: Spyware hitting MacOS

A new backdoor for MacOS systems has been discovered in recent days by ESET researchers. The goal of the malware is to exfiltrate information from the victim system by exploiting cloud storage services.The Backdoor, named by CloudMensis researchers, recovers information such as documents, email messages and attachments, files on removable devices, screenshots and the sequence … Read more

Read the analysis
·Uncategorized

Malware TrickBot – June 2021

An Italian malspam campaign has been identified with the objective of delivering TrickBot malware via an Excel attachment. The malware has been traced back to the sat1 botnet. TrickBot is a banking trojan developed to steal login credentials for victims’ banking sites through the use of webinjects. Since June 2018, TrickBot has been upgraded with … Read more

Read the analysis
Blog home