BSides Frankfurt: Deconstructing Modern macOS Initial Access Vectors
Abstract For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.
We will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).