![xiu Profile](https://pbs.twimg.com/profile_images/1686697299374735360/b2ikQXcT_x96.jpg)
xiu
@osint_barbie
Followers
628
Following
2K
Statuses
561
OSINT enthusiast | malware researcher at @moonlock_lab | opinions and tweets are my own
Joined August 2023
we all know our nerdy souls craved code snippets and juicy IOCs (they’re coming at the end of thread😉)
1/10: We got tagged by @NietzscheLab under a post about a suspicious PyPI package targeting macOS users. It led to an article exposing the “Meme-Token-Hunter-Bot” on GitHub. Naturally, we had to check it out and sketch the hidden attack flow ourselves. Here’s what we found 👇
0
0
12
RT @bruce_k3tta: #Poseidon #stealer for #macos with low detections lol "poseidon[.]cool" domain points to its C2 saves zip in /tmp/pizd…
0
13
0
RT @vmray: 🚨 Alert: Fully undetected Shell Script dropping macOS Atomic Stealer📷 💻 A DMG file containing a malicious Shell Script used to…
0
21
0
@vmray great work! thank you for tagging me🩶 keep me in the loop if you find more macOS samples;)
0
0
2
Great analysis of macOS samples from @SentinelOne related to the campaign reported by @tayvano_ 👏💪 I was lucky enough to check out this interview myself, what a win to see it before it disappeared )🍀
🚨 Alert: New macOS Malware Variants, FlexibleFerret, Undetected by Apple’s XProtect 🚨 @LabsSentinel researchers @philofishal and @TomHegel have uncovered new variants, which slip past Apple's XProtect, of the DPRK-linked macOS malware, Ferret. Dive deeper into our findings to stay ahead of this sophisticated threat: Key Insights: 👉 Detailed analysis of the malware's capabilities, part of the ongoing Ferret family campaign. 👉 Comprehensive list of indicators for threat hunters and defenders to identify and mitigate the threat. 👉 Threat actors are dynamically adapting, moving from signed to unsigned applications to evade detection. 👉 Both targeted attacks and broader 'scatter gun' approaches via social media and platforms like GitHub. @LabsSentinel continues to track and publicize these activities to bolster community defenses. SentinelOne customers are protected from all known variants of the Ferret family.
0
3
28
@jamieantisocial when I told my bestie about state-sponsored hackers, stuxnet, and MaaS, she looked at me like I had just escaped from a psych ward 🥲
1
0
5
woooow well done 💪👏
Well this took all of January, but that's a wrap! Mahalo for following along 🙏🏽 I've just uploaded a (100 page+) PDF of the complete blog post: Also all samples in the report have been made available for download #SharingIsCaring 🍎👾🥰
0
0
5
RT @KandjiOfficial: Infostealers targeting macOS are evolving rapidly, making continuous monitoring essential, which our team is always on…
0
14
0
RT @privacyis1st: Another Mac Appstore AI Scam. Fail OpenAI Scam App converted by the scammer in @deepseek_ai by impersonating the DeepSeek…
0
5
0