Colin Cowie · @th3_protoCOL
634 followers · 171 posts · Server infosec.exchange

Day 1️⃣​0️⃣​ of : MacOS Browser Hijacker Scripts🍎​
🔗​ github.com/colincowie/100DaysO

Background on these MacOS malware scripts used by aka :
📖​ redcanary.com/blog/chromeloade
📖​ blogs.vmware.com/security/2022
📖​ th3protocol.com/2022/Choziosi-

Todays rule did a nice job of detecting the historical ChromeLoader scripts. A more generic yara rule for identifying .command script abuse would potentially be pretty interesting!

#100DaysofYARA #ChromeLoader #choziosiloader

Last updated 3 years ago