Melting Pot of macOS Malware Adds Go to Crystal, Nim and Rust Variants
ReaderUpdate, a macOS malware loader platform active since 2020, has evolved to include variants written in Crystal, Nim, Rust, and now Go programming languages. Originally a compiled Python binary, the malware has been largely dormant until late 2024. The loader is capable of executing remote commands, potentially offering Pay-Per-Install or Malware-as-a-Service. It collects system information, creates persistence mechanisms, and communicates with command and control servers. The Go variant, less common than others, uses string obfuscation techniques to hinder analysis. While currently associated with adware delivery, the loader's capabilities pose a potential threat for more malicious payloads in the future.
Pulse ID: 67e41bedc264bcc69a9b8e20
Pulse Link: https://otx.alienvault.com/pulse/67e41bedc264bcc69a9b8e20
Pulse Author: AlienVault
Created: 2025-03-26 15:23:25
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
