Essential macOS Stealer - script.sh
A multi-stage macOS infostealer delivered as an AppleScript one-liner that installs a LaunchAgent for persistence and resolves its C2 domain via a public blockchain smart-contract call.
Welcome! On this website you will find a new malware sample analysis every week.
There is no required order to follow. You can simply search for any sample you want to analyze.
The idea is simple: I provide the download link for the sample, and you perform the analysis yourself. You can then read my report and compare it with your results. More information about why this website exists is available on the About page.
A multi-stage macOS infostealer delivered as an AppleScript one-liner that installs a LaunchAgent for persistence and resolves its C2 domain via a public blockchain smart-contract call.
A PyInstaller-packed Python loader that patches AMSI and ETW, checks for sandboxes, then drops an obfuscated .NET dropper which deploys a Venom/AsyncRAT-lineage remote access trojan. The RAT persists through startup, registry and scheduled tasks, and supports keylogging, screen and webcam capture, credential theft, file encryption and USB spreading.
A fully fledged modular infostealer targeting browser, Discord and Mail clients.
Type to search every report and article.