No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

macOS Malware Campaign Showcases Novel Delivery Technique

February 2, 2024
in Protection
0
macOS Malware Campaign Showcases Novel Delivery Technique


Security researchers have sounded the alarm on a new cyberattack campaign using cracked copies of popular software products to distribute a backdoor to macOS users.

What makes the campaign different from numerous others that have employed a similar tactic — such as one reported just earlier this month involving Chinese websites — is its sheer scale and its novel, multistage payload delivery technique. Also noteworthy is the threat actor’s use of cracked macOS apps with titles that are of likely interest to business users, so organizations that don’t restrict what users download can be at risk as well.

Kaspersky was the first to discover and report on the Activator macOS backdoor in January 2024. A subsequent analysis of the malicious activity by SentinelOne has showed the malware to be “running rife through torrents of macOS apps,” according to the security vendor.

“Our data is based on the number and frequency of unique samples that have appeared across VirusTotal,” says Phil Stokes, a threat researcher at SentinelOne. “In January since this malware was first discovered, we’ve seen more unique samples of this than any other macOS malware that we [tracked] over the same period of time.”

The number of samples of the Activator backdoor that SentinelOne has observed is more than even the volume of macOS adware and bundleware loaders (think Adload and Pirrit) that are supported by large affiliate networks, Stokes says. “While we have no data to correlate that with infected devices, the rate of unique uploads to VT and the variety of different applications being used as lures suggests that in-the-wild infections will be significant.”

Building a macOS Botnet?

One potential explanation for the scale of the activity is that the threat actor is attempting to assemble a macOS botnet, but that remains just a hypothesis for the moment, Stokes says.

The threat actor behind the Activator campaign is using as many as 70 unique cracked macOS applications — or “free” apps with copy protections removed — to distribute the malware. Many of the cracked apps have business-focused titles that could be of interest to individuals in workplace settings. A sampling: Snag It, Nisus Writer Express, and Rhino-8, a surface modeling tool for engineering, architecture, automotive design, and other use cases.

“There are many tools useful for work purposes that are used as lures by macOS.Bkdr.Activator,” Stokes says. “Employers that do not restrict what software users can download could be at risk of compromise if a user downloads an app that is infected with the backdoor.”

Threat actors seeking to distribute malware via cracked apps typically embed the malicious code and backdoors within the app itself. In the case of Activator, the attacker has employed a somewhat different strategy to deliver the backdoor.  

Different Delivery Method

Unlike many macOS malware threats, Activator doesn’t actually infect the cracked software itself, Stokes says. Instead, users get an unusable version of the cracked app they want to download, and an “Activator” app containing two malicious executables. Users are instructed to copy both apps to the Applications folder, and run the Activator app.

The app then prompts the user for the admin password, which it then uses to disable macOS’ Gatekeeper settings so that applications from outside Apple’s official app store can now run on the device. The malware then initiates a series of malicious actions that ultimately turn off the systems notifications setting and install a Launch Agent on the device, among other things. The Activator backdoor itself is a first-stage installer and downloader for other malware.

The multistage delivery process “provides the user with the cracked software, but backdoors the victim during the installation process,” Stokes says. “This means that even if the user later decided to remove the cracked software, it will not remove the infection.”

Sergey Puzan, malware analyst at Kaspersky, points to another aspect of the Activator campaign that is noteworthy. “This campaign uses a Python backdoor that doesn’t appear on disk at all and is launched directly from the loader script,” Puzan says. “Using Python scripts without any ‘compilers’ such as pyinstaller is a bit more tricky as it require attackers to carry a Python interpreter at some attack stage or ensure that the victim has a compatible Python version installed.”

Puzan also believes that one potential goal of the threat actor behind this campaign is to build a macOS botnet. But since Kaspersky’s report on the Activator campaign, the company has not observed any additional activity, he adds.



Editorial Team

Editorial Team

Related Posts

My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale
Protection

My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale

March 26, 2026
Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It's $140 Off During Amazon's Big Spring Sale
Protection

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It’s $140 Off During Amazon’s Big Spring Sale

March 26, 2026
The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon's Big Spring Sale
Protection

The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon’s Big Spring Sale

March 26, 2026
This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale
Protection

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale

March 26, 2026
What Happens Now That Meta and YouTube Were Found Legally Negligent
Protection

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
If I Had a Home Gym, This Is the Storage Rack I'd Buy During Amazon's Spring Sale
Protection

If I Had a Home Gym, This Is the Storage Rack I’d Buy During Amazon’s Spring Sale

March 26, 2026
Load More
Next Post
Analyst Report: Illinois Tool Works, Inc.

Analyst Report: Illinois Tool Works, Inc.

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • SC Lowy to launch interval fund amid private credit pivot

    0 shares
    Share 0 Tweet 0
  • The Best Luxury Hotels in Kansas City, Whether You’re Visiting for Barbecue or the World Cup

    0 shares
    Share 0 Tweet 0

Latest News

UK moves to freeze crypto donations in politics

UK moves to freeze crypto donations in politics

March 26, 2026
0

The UK government is moving toward a temporary ban on political donations made through cryptocurrencies after a fresh review raised...

My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale

My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale

March 26, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Karen Hao: Profit motives drive AI development, current technologies harm society, and labor exploitation is rampant in the industry

Karen Hao: Profit motives drive AI development, current technologies harm society, and labor exploitation is rampant in the industry

March 26, 2026
0

Key takeaways AI development is driven by profit motives, potentially leading to superior civilizations. Current AI technologies are causing significant...

Bitcoin

Bitcoin Activity Index Keeps Declining: Demand Still Weak?

March 26, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure CryptoQuant’s Network Activity Index for Bitcoin has...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.