Objective-See Foundation (@objective_see) 's Twitter Profile
Objective-See Foundation

@objective_see

๐ŸŽ ๐Ÿ›ก๏ธ
๐Ÿ› ๏ธ Open-Source Tools
๐Ÿ“š "The Art of Mac Malware" books
๐Ÿซ‚ "Objective by the Sea" conference

Support us on patreon.com/objective_see ๐Ÿ™

ID: 401009490

linkhttp://objective-see.org calendar_today29-10-2011 22:28:39

4,4K Tweet

18,18K Followers

1 Following

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Haven't found a clear answer, but lldb's "target.process.follow-fork-mode child" on macOS is broken, ya? (ChatGPT concurs, esp. when Rosetta comes into play). Here we can see that after fork() is executed ....we're still in the parent (RAX is the pid of the child process) ๐Ÿ˜ฃ

Haven't found a clear answer, but lldb's "target.process.follow-fork-mode child" on macOS is broken, ya?

(ChatGPT concurs, esp. when  Rosetta comes into play).

Here we can see that after fork() is executed
....we're still in the parent (RAX is the pid of the child process) ๐Ÿ˜ฃ
Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

We're looking to fill the final trainer slot for a free (half- or full-day) workshop at our next #OFTW event! ๐Ÿ—“๏ธ Date: July 24th ๐Ÿ“ Location: London ๐Ÿ’ป Topics: beginner-friendly cybersecurity (ideally Apple-related). Interested? DM me or email [email protected] ๐Ÿ™๐Ÿฝ

We're looking to fill the final trainer slot for a free (half- or full-day) workshop at our next #OFTW event! 

๐Ÿ—“๏ธ Date: July 24th
๐Ÿ“ Location: London
๐Ÿ’ป Topics: beginner-friendly cybersecurity (ideally Apple-related).

Interested? DM me or email oftw@objective-see.com ๐Ÿ™๐Ÿฝ
Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Security & Usability are often (unfortunately) at odds with each other. Here's a (hilarious) example: Apparently: "if you send an audio message (via iMsg) that includes โ€œDave and Buster'sโ€ the message will never be received" ๐Ÿ‘€ ...cuz of BlastDoor ๐Ÿ˜‚ rambo.codes/posts/2025-05-โ€ฆ

Security & Usability are often (unfortunately) at odds with each other. Here's a (hilarious) example: 

Apparently: "if you send an audio message (via iMsg) that includes โ€œDave and Buster'sโ€ the message will never be received" ๐Ÿ‘€ 

...cuz of BlastDoor ๐Ÿ˜‚

rambo.codes/posts/2025-05-โ€ฆ
Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Stoked to announce #OFTW v3.0 ๐Ÿฅณ This *free* student-centric event provides ๐Ÿ trainings & talks! ๐Ÿ“ London ๐Ÿ—“๏ธ July 24-25th Note: Due to limited space you must apply to attend โ„น๏ธMore info/apply: objective-see.org/oftw/v3.html Mahalo to Kandji for supporting this event!

Marcelo Rivero (@marcelorivero) 's Twitter Profile Photo

#Cthulhu Stealer for #macOS ๐Ÿ™ โ€” nothing new under the hood, just repacked. ๐Ÿงฑ Wails-based ๐Ÿงช No code changes โ€” same steal logic ๐ŸŒ C2: 89[.]208.103[.]185 ๐Ÿงฌ #AMOS DNA all over it ๐Ÿ“ฆ Dropped at: /Users/Shared/NW/[CH]Cthulhu_Mac_OS_[date].zip ๐Ÿ”— x.com/malwrhunterteaโ€ฆ

#Cthulhu Stealer for #macOS ๐Ÿ™ โ€” nothing new under the hood, just repacked.

๐Ÿงฑ Wails-based  
๐Ÿงช No code changes โ€” same steal logic  
๐ŸŒ C2: 89[.]208.103[.]185  
๐Ÿงฌ #AMOS DNA all over it  
๐Ÿ“ฆ Dropped at:  
/Users/Shared/NW/[CH]Cthulhu_Mac_OS_[date].zip

๐Ÿ”— x.com/malwrhunterteaโ€ฆ
Moonlock Lab (@moonlock_lab) 's Twitter Profile Photo

1/4: Moonlock Lab team notifies about an ongoing campaign involving #Odyssey #macOS #stealer and others utilizing Gatekeeper bypass. Started in early May and has been going on until today. Our analytics system has noticed an anomalous increase in observed samples among our users.

1/4: Moonlock Lab team notifies about an ongoing campaign involving #Odyssey #macOS #stealer and others utilizing Gatekeeper bypass. Started in early May and has been going on until today. Our analytics system has noticed an anomalous increase in observed samples among our users.
Luke Roberts (@rookuu_) 's Twitter Profile Photo

This is going to be a lot of fun! ๐ŸŽ I'll be talking about macOS tradecraft and internal red teaming more generally. Attendance is completely free and gives access to the talks and trainings. If you're a student or are starting your career in security, check it out! ๐Ÿค™

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

New from Lorenzo Franceschi-Bicchierai, confirmation that the advanced cross-platform cyberespionage backdoor 'Careto' was (as long suspected?) run by Spain ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‘€ Read: "Mysterious hacking group Careto was run by the Spanish government": techcrunch.com/2025/05/23/mysโ€ฆ

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

In 2016 I took a look at the macOS variant ...which you can find in Objective-See Foundation's public macOS malware repository: github.com/Objective-see/โ€ฆ #SharingIsCaring

In 2016 I took a look at the macOS variant ...which you can find in <a href="/objective_see/">Objective-See Foundation</a>'s public macOS malware repository: github.com/Objective-see/โ€ฆ

#SharingIsCaring
Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Trainings for #OBTS v8 are already starting to sell out! So if you're planning to take a training, now's the time to grab your spot โณ View & sign up: objectivebythesea.org/v8/trainings.hโ€ฆ

Trainings for #OBTS v8 are already starting to sell out! 

So if you're planning to take a training, now's the time to grab your spot โณ

View &amp; sign up:
objectivebythesea.org/v8/trainings.hโ€ฆ
Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Stoked to be hosting an introductory macOS malware analysis workshop at the "Malware Village" at DEF CON! ๐Ÿ‘จ๐Ÿปโ€๐Ÿซ๐Ÿ๐Ÿ›๐Ÿ‘พ #defcon33 Space is limited, so if you're interested (and want some free books too!), apply via the Malware Village form: forms.gle/Ruy7FyCe8fcHdhโ€ฆ

Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Not only is Huntress a generous supporter of our Foundation, they also consistently publish top-notch research on emerging macOS threats ๐Ÿคฉ Their latest (by alden & Stuart Ashenbrenner ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡จ๐Ÿ‡ฆ): "Feeling Blue(Noroff): Inside a Sophisticated DPRK Web3 Intrusion": huntress.com/blog/inside-blโ€ฆ

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

โณ Just one week left to submit your talk to #OBTS v8 objectivebythesea.org/v8/cfp.html (CFP closes June 30th). Weโ€™ve expanded toย 3 daysย of talks this year, making room for even more cutting-edge researchย + ย first-time speakers. So submit your Apple security-themed proposal today!

Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Stoked Fleet (fleetdm.com) has joined our "Friends of Objective-See" as a Platinum-tier supporter! ๐Ÿ’Ž Their supports ensures our: ๐Ÿ› ๏ธ open-source tools ๐Ÿ“š free #TAOMM book(s) ๐Ÿค— community-driven #OBTS & #OFTW conferences ...will all continue to thrive and grow!